CVE-2026-18608

8.7

Red Hat · OpenShift AI

A vulnerability in the Data Science Pipelines Operator for Red Hat OpenShift AI allows for execution with unnecessary privileges.

Executive summary

The Data Science Pipelines Operator in Red Hat OpenShift AI is susceptible to a privilege escalation flaw that could lead to unauthorized system-wide impact.

Vulnerability

This flaw stems from execution with unnecessary privileges (CWE-250) within the Data Science Pipelines Operator (DSPO). The CVSS vector confirms that an authenticated attacker with high privileges can exploit this via network access to cause a scope change and compromise system integrity and confidentiality.

Business impact

With a CVSS score of 8.7, this vulnerability poses a severe risk to the entire OpenShift cluster environment. Successful exploitation could allow an attacker to bypass security boundaries, potentially leading to cross-namespace data access or unauthorized modification of critical pipeline configurations.

Remediation

Immediate Action: Apply the vendor security update to Red Hat OpenShift AI 3.3, ensuring the Data Science Pipelines Operator is updated to version 1785187936 or later per RHSA-2026:53263.

Proactive Monitoring: Monitor for anomalous pipeline activity or unexpected changes to cluster-wide settings and operator configurations.

Compensating Controls: Enforce tight security context constraints and limit access to the Data Science Pipelines Operator to only authorized administrative personnel.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for a scope-changing impact on the OpenShift cluster, this issue must be addressed with high urgency. Administrators should verify their current version of the Data Science Pipelines Operator and apply the necessary patches provided by Red Hat without delay.

More Red Hat CVEs