Status: UPDATED
| Advisory ID: CVE-2026-18982
Key Details
| CVE | CVE-2026-18982 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-09-21 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat OpenShift AI 3.3, Red Hat Red Hat OpenShift AI 3.4, Red Hat Red Hat OpenShift AI 2.25, and Red Hat Red Hat OpenShift AI 3.5 |
| Classified as | CWE-250 (Execution with Unnecessary Privileges) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References