What is CVE-2026-15218?
A flaw was found in Red Hat OpenShift AI where the maas-api and maas-controller ServiceAccounts are granted excessive cluster-wide permissions. If an attacker compromises the identity of these ServiceAccounts, they could gain full control of the system. It is recommended to restrict these permissions to the minimum necessary.
Azərbaycanca: Red Hat OpenShift AI-də maas-api və maas-controller xidmət hesablarına həddindən artıq geniş klaster səviyyəli icazələr verilməsi zəifliyi aşkarlanıb. Bu xidmət hesablarından hər hansı birinin eyniləşdirməsi ələ keçirilərsə, hücumçu sistemi tam ələ keçirə bilər. Bu hesabların icazələrini minimuma endirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which ServiceAccounts are affected by CVE-2026-15218 in Red Hat OpenShift AI?
This flaw affects the maas-api and maas-controller ServiceAccounts.
What can an attacker achieve by exploiting CVE-2026-15218?
If an attacker compromises the identity of one of these ServiceAccounts, they could gain full control of the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.