CVE-2026-18617
8.8Red Hat · OpenShift AI
A security flaw in the Data Science Pipelines Operator for Red Hat OpenShift AI 3.3 allows for improper control of object attributes.
Executive summary
Red Hat OpenShift AI 3.3 is vulnerable to a high-severity flaw in the Data Science Pipelines Operator that could lead to unauthorized attribute modification.
Vulnerability
The vulnerability relates to the improper control of dynamically determined object attributes (CWE-915) within the Data Science Pipelines Operator. It requires an authenticated user with low privileges to trigger the flaw.
Business impact
An authenticated attacker could leverage this flaw to modify system attributes, potentially leading to unauthorized control over pipeline execution or data access. With a CVSS score of 8.8, this represents a significant risk to the integrity and reliability of the data science workflows running on the OpenShift platform.
Remediation
Immediate Action: Update to the fixed version of Red Hat OpenShift AI, which includes the necessary security fixes for the Data Science Pipelines Operator.
Proactive Monitoring: Review pipeline configuration changes and audit logs for the Data Science Pipelines Operator to detect any unauthorized modifications to object attributes.
Compensating Controls: Restrict access to pipeline management interfaces to only necessary personnel and implement strict validation for any dynamic configuration inputs.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score, it is imperative to apply the provided vendor updates for Red Hat OpenShift AI 3.3 immediately. Failure to patch may expose pipeline operations to unauthorized manipulation and system-level risks.