THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18982 (HIGH 8.8) — A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host files

[NVD] CVE-2026-18982 (HIGH 8.8) — A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host files

lownvdPublished 2026-08-10

CVE-2026-18982 CVSS: 8.8 HIGH Published: 2026-08-10T21:17:21.833

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18982