漏洞情报聚合

CVE-2026-18608 - A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these privileges to gain full administrative control over the entire Kubernetes cluster. - 漏洞详情

漏洞编号:CVE-2026-18608

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-18608

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-250

发布/更新时间:2026-08-10 / 2026-08-27

漏洞描述

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If the DSPO pod were compromised, an attacker could leverage these privileges to gain full administrative control over the entire Kubernetes cluster.

相关链接

相关漏洞

« 返回首页