CVE-2026-15218

Source
https://cve.org/CVERecord?id=CVE-2026-15218
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15218.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15218
Published
2026-08-17T13:39:18Z
Modified
2026-10-08T02:49:45Z
Severity
  • 7.9 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts with excessive permissions lead to privilege escalation
Details

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-266"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15218.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "*"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/opendatahub-io/models-as-a-service

Affected ranges

Type
GIT
Repo
https://github.com/opendatahub-io/models-as-a-service
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15218.json"