CVE-2026-18951: Red Hat Openshift Ai 3.3
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution.
Affected products
- Red Hat Red Hat Openshift Ai 3.3: before 1785188461 (fixed in 1785188461); before 1790137153 (fixed in 1790137153)
- Red Hat Red Hat Openshift Ai 3.4: before 1784814352 (fixed in 1784814352); before 1787361677 (fixed in 1787361677)
- Red Hat Red Hat Openshift Ai 3.5: before 1786552271 (fixed in 1786552271); before 1786552250 (fixed in 1786552250)
Published 2026-08-10. Last modified 2026-09-30.