PT-2026-69968 · Red Hat · Rhoai Training-Operator
CVE-2026-18982
·
Published
2026-08-10
·
Updated
2026-08-27
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RHOAI training-operator (affected versions not specified)
Description
A flaw allows users with standard edit or admin roles in any Kubernetes namespace to escalate privileges. By creating training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This occurs because training job permissions are aggregated into native Kubernetes edit and admin ClusterRoles, combined with unrestricted
PodTemplateSpec passthrough.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rhoai Training-Operator