漏洞情报聚合

CVE-2026-15218 - A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through - 漏洞详情

漏洞编号:CVE-2026-15218

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-15218

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-266

发布/更新时间:2026-08-17 / 2026-08-27

漏洞描述

A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.

相关链接

相关漏洞

« 返回首页