PT-2026-69956 · Minio+2 · Minio+2

CVE-2026-18611

·

Published

2026-08-10

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Data Science Pipelines Operator (affected versions not specified)
Description A flaw exists where the operator uses a cryptographically weak pseudo-random number generator (PRNG)—a mathematical algorithm used to generate sequences of numbers that appear random but are actually deterministic—to create sensitive credentials. This makes MariaDB root/user passwords and MinIO access/secret keys predictable. An unauthenticated attacker with access to the MinIO Route or MariaDB Service can derive these credentials, potentially leading to unauthorized access to all pipeline artifacts and metadata.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18611

Affected Products

Data Science Pipelines Operator
Mariadb
Minio