CVE-2026-18621

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 21:17

Updated : 2026-09-08 22:17


NVD link : CVE-2026-18621

Mitre link : CVE-2026-18621

CVE.ORG link : CVE-2026-18621


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment