What is CVE-2026-18620?
This vulnerability in Data Science Pipelines allows a restricted user to exploit improper authorization in the setDefaultServiceAccount function during a CreateRun request, enabling the specification of a more privileged ServiceAccount and bypassing security checks. Affected users should immediately review and update their authorization logic and access controls to prevent privilege escalation.
Azərbaycanca: Data Science Pipelines-də aşkar edilmiş bu zəiflik, məhdud səlahiyyətli istifadəçinin CreateRun sorğusu zamanı setDefaultServiceAccount funksiyasındakı səhv avtorizasiya yoxlamasından istifadə edərək daha yüksək imtiyazlı ServiceAccount-unu təyin etməsinə imkan verir. Bu, təcavüzkara icazəsiz əməliyyatlar icra etmək üçün sistemdəki məhdudiyyətləri keçməyə şərait yaradır. Təsirə məruz qalan istifadəçilər giriş nəzarətlərini dərhal nəzərdən keçirməli və avtorizasiya funksiyalarını yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does the CVE-2026-18620 vulnerability in Data Science Pipelines allow a restricted user to do?
This vulnerability allows a restricted user to exploit improper authorization in the setDefaultServiceAccount function during a CreateRun request to specify a more privileged ServiceAccount.
What measures should be taken to mitigate the CVE-2026-18620 vulnerability?
Affected users should immediately review and update their authorization logic and access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.