CVE-2026-18621

7.6

Red Hat · OpenShift AI

A flaw in Red Hat OpenShift AI Data Science Pipelines (DSP) allows authenticated users to gain elevated privileges due to incorrect privilege assignment.

Executive summary

A high-severity privilege assignment vulnerability in Red Hat OpenShift AI 3.3 could allow authenticated users to perform unauthorized actions.

Vulnerability

This vulnerability is categorized as CWE-266, involving incorrect privilege assignment within the Data Science Pipelines component. It requires the attacker to have low-level authenticated access to the system to exploit the flaw.

Business impact

Successful exploitation of this flaw could allow an authenticated user to gain access or permissions beyond their intended scope, potentially leading to unauthorized data modification or system impact. Given the CVSS score of 7.6, this represents a significant risk to the integrity and confidentiality of the AI pipeline environment.

Remediation

Immediate Action: Update Red Hat OpenShift AI 3.3 to the version containing the fix, identified as build 1785187920 or later.

Proactive Monitoring: Monitor system logs for unusual permission changes or unauthorized attempts to access pipeline configurations.

Compensating Controls: Restrict access to the Data Science Pipelines interface to only necessary personnel to minimize the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability presents a clear risk of privilege escalation within the OpenShift AI environment. Administrators should prioritize the deployment of the provided update to ensure that role-based access controls remain enforced and to prevent potential unauthorized escalation of privileges.

More Red Hat CVEs