What is CVE-2026-18617?
CVE-2026-18617 is a vulnerability in the Data Science Pipelines Operator (DSPO) that allows a namespace editor to inject dangerous parameters into the MySQL DSN string via the "spec.database.customExtraParams" field. This could enable an attacker to compromise the database connection; applying vendor patches and restricting namespace editor access are advised until the fix is deployed.
Azərbaycanca: CVE-2026-18617, Data Science Pipelines Operator (DSPO) servisində "spec.database.customExtraParams" sahəsi vasitəsilə MySQL DSN string-ə təhlükəli parametr inject etməyə imkan verən boşluqdur. Bu zəiflik namespace editor səlahiyyətinə malik istifadəçiyə məlumat bazasına müdaxilə etmə riskini yaradır; DSPO istifadəçiləri yamaq tətbiq edilənə qədər etibarsız istifadəçilərə editor rolu verməməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
How can CVE-2026-18617 be exploited in the Data Science Pipelines Operator?
A user with namespace editor privileges can inject dangerous parameters into the MySQL DSN string via the “spec.database.customExtraParams” field.
What temporary measure is recommended for CVE-2026-18617 before the official patch is applied?
It is advised not to grant the namespace editor role to untrusted users until the patch is deployed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.