What is CVE-2026-18951?
A flaw was discovered in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`, allowing any user with `edit ClusterRole` permissions in a namespace to create and modify training jobs.
Azərbaycanca: Bu qüsur Red Hat OpenShift AI (RHOAI) overlay-də training operator üçün aşkarlanıb. Səhv konfiqurasiya nəticəsində `trainjobs` idarəetmə icazələri səhvən Kubernetes `edit ClusterRole`-una əlavə edilir və bu, `edit ClusterRole` icazəsi olan istənilən istifadəçiyə həmin namespace-də təlim tapşırıqlarını yaratmaq, dəyişdirmək imkanı verir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Red Hat
FAQ2
Which Kubernetes role incorrectly aggregates the trainjobs management permissions in the RHOAI overlay?
The misconfiguration causes the `trainjobs` management permissions to be incorrectly aggregated into the Kubernetes `edit ClusterRole`.
What capabilities does this flaw grant to users with the `edit ClusterRole` permission?
It allows any user with `edit ClusterRole` permissions in a namespace to create and modify training jobs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.