CVE-2026-18621: Red Hat Ai Inference Server
High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Affected products
- Red Hat Red Hat Ai Inference Server
- Red Hat Red Hat Openshift Ai 2.25: before 1785189934 (fixed in 1785189934); before 1788256711 (fixed in 1788256711)
- Red Hat Red Hat Openshift Ai 3.3: before 1785187920 (fixed in 1785187920)
- Red Hat Red Hat Openshift Ai 3.4: before 1784924951 (fixed in 1784924951); before 1787173417 (fixed in 1787173417)
Published 2026-08-10. Last modified 2026-09-08.