CVE-2026-18949

8.8

Red Hat · OpenShift AI

A vulnerability in the odh-dashboard component of Red Hat OpenShift AI allows authenticated attackers to perform operations with excessive privileges.

Executive summary

A critical privilege escalation vulnerability in Red Hat OpenShift AI 3.3 allows authenticated users to execute actions with unnecessary permissions, potentially leading to full system compromise.

Vulnerability

The vulnerability is identified as CWE-250, which involves execution with unnecessary privileges. The CVSS vector indicates the attack requires low privileges (PR:L) and can be executed over the network (AV:N), allowing an authenticated attacker to perform unauthorized actions.

Business impact

This vulnerability poses a significant risk to the integrity and confidentiality of the OpenShift AI environment. With a CVSS score of 8.8, the ability for a low-privileged user to gain unauthorized elevated access can result in data exfiltration, unauthorized modification of machine learning models, or complete disruption of AI services.

Remediation

Immediate Action: Update Red Hat OpenShift AI 3.3 to the patched version identified by build number 1786109683 or later as specified in RHSA-2026:53263.

Proactive Monitoring: Audit user access logs and monitor for unusual API calls or administrative actions originating from standard user accounts.

Compensating Controls: Implement strict Role Based Access Control (RBAC) policies and use network segmentation to limit the reach of the odh-dashboard component.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity of this vulnerability, administrators should prioritize the application of the provided vendor security updates. Ensuring the software is updated to the specified build version is essential to eliminate the risk of privilege escalation.

More Red Hat CVEs