CVE-2026-18621High· 7.6▾ TwilightA flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15467High· 8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller
CVE-2026-18620High· 7.1A flaw was found in Data Science Pipelines
CVE-2026-84716Medium· 6.6A flaw was found in the automation-controller instance install-bundle endpoint
CVE-2026-10059Critical· 9.1A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller
CVE-2025-2843High· 8.8A flaw was found in the Observability Operator
CVE-2026-71468Medium· 5.3A flaw was found in acm-search-v2-api-rhel9