THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18617 (HIGH 8.8) — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these

[NVD] CVE-2026-18617 (HIGH 8.8) — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these

lownvdPublished 2026-08-10

CVE-2026-18617 CVSS: 8.8 HIGH Published: 2026-08-10T21:17:20.250

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable LOCAL INFILE functi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18617