What is CVE-2026-18608?
CVE-2026-18608 is a flaw in the Data Science Pipelines Operator (DSPO) where its ClusterRole holds excessive permissions. Unnecessary privileges, like command execution in pods, extend beyond its operational needs. Mitigation involves updating or manually restricting the ClusterRole to the principle of least privilege.
Azərbaycanca: CVE-2026-18608, Data Science Pipelines Operator-da (DSPO) aşkar edilmiş zəiflikdir. Operatorun ClusterRole icazələri həddindən artıq geniş olub, pod-larda əmr icra etmə kimi lüzumsuz imtiyazlar verir. Bu problemi aradan qaldırmaq üçün minimal tələb olunan icazələrə endirilmiş yenilənmiş versiyaya keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
In which component was the CVE-2026-18608 vulnerability discovered?
It was discovered in the Data Science Pipelines Operator (DSPO).
What is the root cause of CVE-2026-18608?
The ClusterRole permissions of the Operator are excessively broad.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.