Sceawere
Vulnerability Detail
CVE-2026-15218UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Red Hat OpenShift AI Excessive ServiceAccount Privileges
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.9
- Creation Date
- 7h ago
- Vendor
- Red Hat
- Product
- Red Hat OpenShift AI (RHOAI)
- Attack Type
- Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.9",
"pubDate": "2026-08-17T14:20:19.357Z",
"pubdate": "2026-08-17T14:20:19.357Z",
"executiveSummary": "An excessive privileges vulnerability has been identified within the maas-api and maas-controller ServiceAccounts in Red Hat OpenShift AI.\nThe vulnerability stems from these ServiceAccounts being assigned overly permissive cluster-wide permissions that far exceed their standard operational requirements.\nAn attacker capable of compromising the identity of either ServiceAccount—such as by leveraging a remote code execution vulnerability or deploying a malicious pod within the same namespace—can abuse these excessive permissions.\nSuccessful exploitation of this flaw can result in a severe security breach, granting the adversary full cluster administrator privileges.\nThis escalation vector enables attackers to create arbitrary ClusterRoleBindings or harvest sensitive information by accessing all secrets stored across the entire Kubernetes cluster.\nThe risk implication is critical, as compromise of the affected components directly undermines the security posture of the entire OpenShift cluster.\nMitigation requires restricting the RBAC permissions assigned to the maas-api and maas-controller ServiceAccounts to adhere strictly to the principle of least privilege.",
"technicalDetails": "The vulnerability resides in the Role-Based Access Control (RBAC) configuration of the maas-api and maas-controller components within Red Hat OpenShift AI.\nThe root cause is an overly broad permission assignment where the associated ServiceAccounts are granted cluster-wide privileges that surpass their necessary operational scope.\nThe affected components comprise the maas-api and maas-controller ServiceAccounts and their underlying RBAC bindings.\nExploitation requires initial access to the targeted namespace or the execution context of the vulnerable services. An attacker can achieve this by exploiting an independent remote code execution vulnerability within the application runtime or by scheduling a malicious pod directly into the same namespace.\nOnce the attacker successfully compromises the identity or token of the maas-api or maas-controller ServiceAccount, the attack flow proceeds through the abuse of the inherited overly broad permissions.\nArmed with these excessive cluster-wide privileges, the adversary can interact with the Kubernetes API server to perform unauthorized administrative actions.\nSpecifically, the attacker can create new ClusterRoleBindings to assign cluster-administrator roles to their own controlled identities, thereby achieving complete persistence and control over the cluster.\nAdditionally, the malicious actor can leverage the excessive permissions to read and exfiltrate sensitive data, including accessing all Kubernetes secrets across every namespace in the cluster.\nThe privilege requirement for the secondary phase is implicitly satisfied by acquiring the ServiceAccount token, and the network exposure is localized to the Kubernetes API server interactions permitted by the initial authorization context."
}