CVE-2026-18948

9.9

Red Hat · Red Hat OpenShift AI

A deserialization flaw in the Feast component of Red Hat OpenShift AI allows remote attackers to execute arbitrary code via malicious user-defined functions.

Executive summary

A critical arbitrary code execution vulnerability exists in Red Hat OpenShift AI due to improper deserialization of user-defined functions, posing a severe threat to feature server security.

Vulnerability

The vulnerability arises from the improper deserialization of UDFs using the dill library, which can be exploited by an attacker to run arbitrary code on the feature or registry servers. While the attack vector is network-based, the impact is severe, allowing for cross-tenant data access and lateral movement within the OpenShift environment.

Business impact

Successful exploitation allows an attacker to gain full control over the feature server, leading to the potential theft of sensitive training data or the corruption of machine learning pipelines. The CVSS score of 9.9 underscores the critical nature of this flaw, as it undermines the security foundation of the platform and could lead to complete system compromise.

Remediation

Immediate Action: Update Red Hat OpenShift AI 3.3 to the fixed release, which is available from version 1786110033 and later.

Proactive Monitoring: Monitor server logs for suspicious process execution or unexpected file system modifications initiated by the Feast registry or feature server services.

Compensating Controls: Implement strict input validation for all user-defined code and restrict access to the registry server to only authorized administrative personnel.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant risk to the integrity of the data science lifecycle. Administrators should treat this as a high-priority update and verify that all affected nodes in the OpenShift AI environment are running the corrected version immediately.

More Red Hat CVEs