{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18982/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18982"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RHOAI training-operator"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cloud-security","kubernetes","cve-2026-18982"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-18982 describes a critical security flaw within the Red Hat OpenShift AI (RHOAI) training-operator. The vulnerability originates from the overly permissive aggregation of training job permissions onto standard native Kubernetes 'edit' and 'admin' ClusterRoles. This configuration, combined with an unrestricted PodTemplateSpec passthrough mechanism, permits users with low-privileged namespace access to define training jobs that escape typical security boundaries.\u003c/p\u003e\n\u003cp\u003eBy crafting specific PodTemplateSpec configurations in a training job request, an attacker can manipulate the job execution environment to impersonate high-privilege service accounts or mount sensitive host filesystems. This leads to full administrative control over the affected cluster and the potential for remote code execution (RCE) on the underlying nodes. The vulnerability primarily impacts environments utilizing the RHOAI training-operator where standard users are granted namespace-level management permissions. Defenders should prioritize patching and restricting ClusterRole assignments for untrusted users to mitigate this vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to escalate privileges to cluster-administrator levels. An attacker can access sensitive data stored in the host filesystem, intercept service account tokens, and execute arbitrary code within the cluster infrastructure. This represents a significant risk to the confidentiality, integrity, and availability of multi-tenant Kubernetes clusters running RHOAI.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the RHOAI training-operator to the vendor-provided patched version immediately.\u003c/li\u003e\n\u003cli\u003eReview and tighten Kubernetes ClusterRole bindings, specifically restricting the 'edit' and 'admin' roles to prevent unintended aggregation of training-operator permissions.\u003c/li\u003e\n\u003cli\u003eAudit existing training job templates for unrestricted PodTemplateSpec configurations that could be leveraged for filesystem mounting.\u003c/li\u003e\n\u003cli\u003eImplement Admission Controllers to validate and reject PodTemplateSpecs that contain suspicious volume mounts or service account references until the patch is deployed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:40:14Z","date_published":"2026-08-10T21:40:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18982/","summary":"A privilege escalation vulnerability in the RHOAI training-operator allows authenticated users with standard Kubernetes edit or admin roles to achieve host filesystem access and remote code execution through the creation of malicious training jobs.","title":"Privilege Escalation in RHOAI training-operator via CVE-2026-18982","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18982/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18982","version":"https://jsonfeed.org/version/1.1"}