---
id: CVE-2026-18620
title: A flaw was found in Data Science Pipelines
summary: >-
  A flaw was found in Data Science Pipelines. A restricted user, or tenant, can
  exploit an improper authorization vulnerability in the
  setDefaultServiceAccount function. By specifying a more privileged
  ServiceAccount (SA) during a CreateRu…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-639
vendor: Red Hat
product: rhoai/odh-ml-pipelines-api-server-v2-rhel9
affected:
  - rhoai/odh-ml-pipelines-api-server-v2-rhel9 (all versions)
  - rhoai/odh-ml-pipelines-api-server-v2-rhel9 (all versions)
  - rhoai/odh-ml-pipelines-api-server-v2-rhel9 (all versions)
  - rhoai/odh-ml-pipelines-api-server-v2-rhel9 (all versions)
  - rhoai/odh-ml-pipelines-api-server-v2-rhel9 (all versions)
  - rhoai/odh-latency-predictor-prediction-rhel9 (all versions)
  - rhoai/odh-latency-predictor-training-rhel9 (all versions)
patched:
  - openshift_ai 2.25
  - openshift_ai 3.3
  - openshift_ai 3.4
published: '2026-08-10'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T12:17:12.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18620'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:53261'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53262'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53263'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60367'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18620'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2510320'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18620.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18620'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18620'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-11T13:32:11.009227Z'
epss: 0.00478
epssPercentile: 0.38767
ingestedAt: '2026-09-08T23:13:54.647Z'
---

## Overview

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclosure of sensitive information (secrets) and the ability to execute commands within other users' pods.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:53261** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53261)
- **RHSA-2026:53263** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53263)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:53262** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53262)
- **RHSA-2026:60367** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60367)
