Authorization Token Theft in Kubeflow Community Distribution
CVE-2026-47237

8HIGH

Key Information:

Vendor

Kubeflow

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47237?

The Kubeflow Community Distribution is susceptible to an authorization token theft vulnerability. This affects users who engage with the Kubeflow UI or APIs – including the Dashboard, Pipelines API, and Notebooks. An attacker can exploit this vulnerability to gain unauthorized access to a user’s account and their processed data, provided they already possess a valid user role such as 'kubeflow-edit' or 'Contributor' within a Kubeflow namespace. This scenario is made possible when the 'Automatic Profile Creation' feature is enabled. It is crucial to update to version 26.03-rc.1 or later to mitigate this security risk.

Affected Version(s)

community-distribution < 26.03-rc.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.