← All Advisories

CVE-2026-18982

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-18982

Key Details

CVECVE-2026-18982
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Red Hat OpenShift AI 3.3, Red Hat Red Hat OpenShift AI 3.4, Red Hat Red Hat OpenShift AI 2.25, and Red Hat Red Hat OpenShift AI 3.5
Classified asCWE-250 (Execution with Unnecessary Privileges)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat OpenShift AI 2.25
Red HatRed Hat OpenShift AI 3.5
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18982
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18982