PT-2026-76650 · Red Hat · Openshift Ai

CVE-2026-15218

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

7.9

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Red Hat OpenShift AI (affected versions not specified)
Description The maas-api and maas-controller ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, through remote code execution or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This may result in the attacker obtaining full cluster administrator privileges by creating new ClusterRoleBindings or disclosing sensitive information by accessing all secrets across the cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15218

Affected Products

Openshift Ai