THREAT OPS › Threat News › [NVD] CVE-2026-18617 (HIGH 8.8) — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these
[NVD] CVE-2026-18617 (HIGH 8.8) — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these
CVE-2026-18617 CVSS: 8.8 HIGH Published: 2026-08-10T21:17:20.250
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable LOCAL INFILE functi
Indicators of compromise
- CVE-2026-18617cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18617