HIGH
CVE-2026-18951
CVSS
8.8
Description
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify, and delete `TrainJobs`. When combined with a separate vulnerability (TRN-01) that permits arbitrary pod configurations, a remote attacker with namespace editor privileges could exploit this to escalate privileges, potentially leading to arbitrary code execution.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
0.57%
Probability of exploitation in next 30 days
45.8th percentile
References
https://access.redhat.com/errata/RHSA-2026:53262
https://access.redhat.com/errata/RHSA-2026:53263
https://access.redhat.com/errata/RHSA-2026:60367
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/security/cve/CVE-2026-18951
https://bugzilla.redhat.com/show_bug.cgi?id=2511187
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.