---
id: CVE-2026-18608
title: A flaw was found in the Data Science Pipelines Operator (DSPO)
summary: >-
  A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's
  ClusterRole, which defines its permissions, includes extensive privileges
  beyond what is necessary for its operation. These excessive permissions, such
  as the…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-250
vendor: Red Hat
product: rhoai/odh-data-science-pipelines-operator-controller-rhel9
affected:
  - rhoai/odh-data-science-pipelines-operator-controller-rhel9 (all versions)
  - rhoai/odh-data-science-pipelines-operator-controller-rhel9 (all versions)
  - rhoai/odh-data-science-pipelines-operator-controller-rhel9 (all versions)
  - rhoai/odh-data-science-pipelines-operator-controller-rhel9 (all versions)
  - rhoai/odh-data-science-pipelines-operator-controller-rhel9 (all versions)
  - rhoai/odh-latency-predictor-prediction-rhel9 (all versions)
  - rhoai/odh-latency-predictor-training-rhel9 (all versions)
patched:
  - openshift_ai 2.25
  - openshift_ai 3.3
  - openshift_ai 3.4
published: '2026-08-10'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T11:17:08.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18608'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:53261'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53262'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53263'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60367'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18608'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510296'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18608.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18608'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18608'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-11T17:15:03.443519Z'
epss: 0.007
epssPercentile: 0.51065
ingestedAt: '2026-09-08T22:12:31.020Z'
---

## Overview

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these privileges to gain full administrative control over the entire Kubernetes cluster.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:53261** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53261)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:53263** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53263)
- **RHSA-2026:53262** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53262)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:60367** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60367)
