Sceawere

Vulnerability Detail

CVE-2026-18982UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RHOAI Training Operator Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Red Hat
Product
Red Hat OpenShift AI (RHOAI)
Attack Type
Execution with Unnecessary Privileges
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-10T21:17:21.833Z",
  "pubdate": "2026-08-10T21:17:21.833Z",
  "executiveSummary": "A privilege escalation vulnerability has been identified in the RHOAI training-operator. The flaw enables authenticated users holding standard edit or admin roles within any Kubernetes namespace to achieve severe privilege escalation across the cluster. The vulnerability stems from improper permission aggregation coupled with an insecurely configured PodTemplateSpec passthrough mechanism within the training job creation workflow.\nAn attacker possessing basic namespace-scoped administrative privileges can exploit this flaw by crafting malicious training jobs. This capability allows the threat actor to impersonate arbitrary service accounts, mount and interact with the underlying host filesystem, and execute arbitrary code remotely. The risk implications are critical, as a successful exploit compromises cluster-wide integrity and confidentiality.\nExploitation requires standard Kubernetes user access with edit or admin permissions inside a target namespace, alongside the ability to submit custom training job definitions to the RHOAI training-operator. No prior administrative cluster privileges are necessary to initiate the attack flow.",
  "technicalDetails": "The root cause of this vulnerability lies in the automatic aggregation of custom training job permissions onto native Kubernetes edit and admin ClusterRoles. When combined with unrestricted PodTemplateSpec passthrough in the RHOAI training-operator, users granted standard namespace editing capabilities inherit overly permissive cluster-level execution contexts.\nThe attack flow proceeds as follows: First, an attacker leverages their existing standard edit or admin role within a controlled Kubernetes namespace. Second, the attacker formulates a malicious custom resource definition payload representing a training job, exploiting the unrestricted PodTemplateSpec passthrough feature. Third, the training-operator processes the job definition, instantiating pods that inherit elevated privileges or impersonate high-privilege service accounts.\nUpon successful pod creation, the execution context allows the attacker to access the underlying host filesystem. By mounting sensitive host paths or leveraging the impersonated service account tokens, the attacker can interact with the Kubernetes API server with elevated credentials, leading to remote code execution and full post-exploitation compromise of the affected node or cluster infrastructure."
}
CVE-2026-18982: RHOAI Training Operator Privilege Escalation (HIGH Severity, CVSS: 8.8) - Sceawere