Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18621

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

Отчет

This is an Important vulnerability in Red Hat OpenShift AI (RHOAI) and Data Science Pipelines Operator (DSPO) that allows a namespace editor to achieve node-root privileges. This occurs because the V1 Argo template path, still active in RHOAI/DSPO deployments, bypasses security hardening applied by the v2 compiler. Exploitation leverages a confused deputy scenario where the API server creates a malicious Workflow CR on behalf of the submitter, enabling privileged pod creation in namespaces configured with GPU operators or anyuid/privileged SCCs.

Меры по смягчению последствий

To mitigate this issue, ensure that Data Science Project (DSP) namespaces enforce pod-security.kubernetes.io/enforce: restricted. Additionally, verify that the pipeline-runner ServiceAccount is not bound to privileged or anyuid Security Context Constraints (SCCs).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Under investigation
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Under investigation
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Under investigation
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Under investigation
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Under investigation
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Under investigation
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Under investigation
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Under investigation
Red Hat AI Inference Serverrhaii/vllm-gaudi-rhel9Under investigation
Red Hat AI Inference Serverrhaii/vllm-neuron-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2510327data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening

EPSS

Процентиль: 28%
0.0035
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.6
nvd
6 дней назад

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

CVSS3: 7.6
github
6 дней назад

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

EPSS

Процентиль: 28%
0.0035
Низкий

7.6 High

CVSS3