THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18608 (HIGH 8.7) — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods an

[NVD] CVE-2026-18608 (HIGH 8.7) — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods an

lownvdPublished 2026-08-10

CVE-2026-18608 CVSS: 8.7 HIGH Published: 2026-08-10T21:17:19.990

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be exploited. If th

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18608