Red Hat OpenShift AI (RHOAI): remote code execution
High7.9CVE-2026-15218 · Published Aug 17, 2026 · updated Aug 27, 2026
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift AI (RHOAI) Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-266
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat managedcluster-import-controller: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat Advanced Cluster Management: improper privilege management | High8.8 | No fix yet |
| Aug 17 | Red Hat acm-search-v2-rhel9. This vulnerability: code execution | Critical9.1 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: missing authentication | Critical9.3 | No fix yet |
| Aug 17 | Red Hat fakefish: command injection | High7.7 | No fix yet |