CVE-2026-18611
7.5Red Hat · OpenShift AI
The Data Science Pipelines Operator in Red Hat OpenShift AI 3.3 contains a flaw where a cryptographically weak pseudo-random number generator is utilized.
Executive summary
A high-severity cryptographic flaw in the Red Hat OpenShift AI Data Science Pipelines Operator could allow unauthenticated attackers to compromise system security.
Vulnerability
This vulnerability is categorized as CWE-338, which involves the use of a cryptographically weak pseudo-random number generator. The attack vector is network-based and does not require prior authentication.
Business impact
The use of weak randomness in security-sensitive operations can lead to the predictability of tokens or keys, potentially allowing an attacker to bypass authentication or decrypt sensitive communications. With a CVSS score of 7.5, this vulnerability poses a serious threat to the overall security posture of the platform.
Remediation
Immediate Action: Update Red Hat OpenShift AI 3.3 to the version containing the fix, identified as build 1785187936 or later.
Proactive Monitoring: Review security logs for anomalous authentication patterns or unexpected cryptographic errors.
Compensating Controls: Utilize a Web Application Firewall to block suspicious traffic patterns and ensure that all network communication is handled via secure, encrypted channels.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the unauthenticated nature of this vulnerability and its potential to weaken critical security controls, immediate patching is required. Organizations should apply the vendor-provided update to replace the weak PRNG and restore the integrity of the cryptographic operations within the Data Science Pipelines Operator.