Product
high
advisory
CVE-2026-18621 Privilege Escalation in Data Science Pipelines
2 TTPs 1 CVEAn attacker with namespace editor privileges can bypass security hardening via the V1 API to execute malicious Argo Workflows, resulting in node-root access.
Data Science Pipelines
2t
1c
high
advisory
Improper Authorization in Data Science Pipelines (CVE-2026-18620)
1 TTP 1 CVEAn authorization bypass vulnerability in Data Science Pipelines allows restricted tenants to execute containers with elevated privileges by specifying a highly-privileged ServiceAccount in a CreateRun request.
Data Science Pipelines
privilege-escalation
kubeflow
cloud-native
1t
1c