CVE-2026-18608
Received Received - Intake

Privilege Escalation in Data Science Pipelines Operator

Vulnerability report for CVE-2026-18608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these privileges to gain full administrative control over the entire Kubernetes cluster.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat data_science_pipelines_operator *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Data Science Pipelines Operator (DSPO) for Kubernetes. The operator's ClusterRole grants excessive permissions beyond what it needs, including the ability to run commands in pods and manage cluster-wide roles. If an attacker compromises the DSPO pod, they could exploit these privileges to gain full administrative control of the entire Kubernetes cluster.

Impact Analysis

If you use the Data Science Pipelines Operator in a Kubernetes environment, an attacker could take over your entire cluster by exploiting this flaw. This could lead to unauthorized access, data theft, service disruption, or further attacks on other systems within the cluster.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using DSPO may face legal penalties, loss of trust, and increased scrutiny due to inadequate security controls.

Mitigation Strategies

Review the Data Science Pipelines Operator's ClusterRole permissions and remove excessive privileges not required for its operation. Limit pod execution and cluster-wide role management capabilities to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart