A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node. | |
| Title | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening | |
| First Time appeared |
Redhat
Redhat ai Inference Server Redhat openshift Ai |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:ai_inference_server:3 cpe:/a:redhat:openshift_ai |
|
| Vendors & Products |
Redhat
Redhat ai Inference Server Redhat openshift Ai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-10T20:44:37.373Z
Reserved: 2026-08-03T08:02:21.941Z
Link: CVE-2026-18621
No data.
No data.
No data.
OpenCVE Enrichment
No data.