Red Hat Data Science Pipelines: API Bypass Grants Node-Root (CVE-2026-18621)
CVE-2026-18621 Published on August 10, 2026

Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

Vendor Advisory Vendor Advisory Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-18621 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
LOW
Availability Impact:
LOW

Timeline

Reported to Red Hat.

Made public. 7 days later.

Weakness Type

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-18621

stack.watch emails you whenever new vulnerabilities are published in Red Hat Ai Inference Server or Red Hat Openshift Ai. Just hit a watch button to start following.

 
 

Affected Versions

Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 3.3: Red Hat OpenShift AI 3.4: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat AI Inference Server: