๐Ÿ” CVE Alert

CVE-2026-18621

HIGH 7.6

Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

CWE CWE-266
Vendor red hat
Product red hat ai inference server
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat ai inference server

Be the first to know when new high vulnerabilities affecting red hat red hat ai inference server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
Low

Affected Versions

Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat AI Inference Server
All versions affected
Red Hat / Red Hat OpenShift AI (RHOAI)
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-18621 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2510327