CVE-2026-18611

7.5

Red Hat · OpenShift AI

The Data Science Pipelines Operator in Red Hat OpenShift AI 3.3 contains a flaw where a cryptographically weak pseudo-random number generator is utilized.

Executive summary

A high-severity cryptographic flaw in the Red Hat OpenShift AI Data Science Pipelines Operator could allow unauthenticated attackers to compromise system security.

Vulnerability

This vulnerability is categorized as CWE-338, which involves the use of a cryptographically weak pseudo-random number generator. The attack vector is network-based and does not require prior authentication.

Business impact

The use of weak randomness in security-sensitive operations can lead to the predictability of tokens or keys, potentially allowing an attacker to bypass authentication or decrypt sensitive communications. With a CVSS score of 7.5, this vulnerability poses a serious threat to the overall security posture of the platform.

Remediation

Immediate Action: Update Red Hat OpenShift AI 3.3 to the version containing the fix, identified as build 1785187936 or later.

Proactive Monitoring: Review security logs for anomalous authentication patterns or unexpected cryptographic errors.

Compensating Controls: Utilize a Web Application Firewall to block suspicious traffic patterns and ensure that all network communication is handled via secure, encrypted channels.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the unauthenticated nature of this vulnerability and its potential to weaken critical security controls, immediate patching is required. Organizations should apply the vendor-provided update to replace the weak PRNG and restore the integrity of the cryptographic operations within the Data Science Pipelines Operator.

More Red Hat CVEs