PT-2026-69968 · Red Hat · Rhoai Training-Operator

CVE-2026-18982

·

Published

2026-08-10

·

Updated

2026-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RHOAI training-operator (affected versions not specified)
Description A flaw allows users with standard edit or admin roles in any Kubernetes namespace to escalate privileges. By creating training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This occurs because training job permissions are aggregated into native Kubernetes edit and admin ClusterRoles, combined with unrestricted PodTemplateSpec passthrough.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18982

Affected Products

Rhoai Training-Operator