A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_ai:2.25::el9 cpe:/a:redhat:openshift_ai:3.4::el9 |
|
| References |
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Ai 3.3
|
|
| Vendors & Products |
Redhat openshift Ai 3.3
|
Tue, 11 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_ai:3.3::el9 | |
| References |
|
Tue, 11 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods. | |
| Title | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods without authorization check — confused deputy | |
| First Time appeared |
Redhat
Redhat openshift Ai |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:openshift_ai | |
| Vendors & Products |
Redhat
Redhat openshift Ai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-08-10T20:45:43.411Z
Updated: 2026-08-11T18:48:26.158Z
Reserved: 2026-08-03T07:57:49.907Z
Link: CVE-2026-18620
Updated: 2026-08-11T13:32:19.130Z
Status : Awaiting Analysis
Published: 2026-08-10T21:17:20.490
Modified: 2026-08-14T19:07:46.080
Link: CVE-2026-18620