Skip to content
Red HatCVE-2026-18621

Red Hat AI Inference Server: code execution

High7.6CVE-2026-18621 · Published Aug 10, 2026 · updated Sep 8, 2026

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat AI Inference Server
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat QEMU: memory corruption
Medium4.4Aug 10
Red Hat Enterprise Linux: denial of service
Low3.9Aug 10
Red Hat Enterprise Linux 10: privilege escalation
High7.8Aug 10
Red Hat OpenShift AI (RHOAI): denial of service
High8.5Aug 10
Red Hat OpenShift AI (RHOAI): remote code execution
Critical9.9Aug 10
Red Hat OpenShift AI (RHOAI): privilege escalation
High8.8Aug 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.