Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-15218

CVE-2026-15218: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.9

    High [CVE-2026-15218] maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation

    CVE-2026-15218Source published Source updated

    A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster. Although exploitation necessitates a prior compromise of a pod or the ability to create pods in the respective namespaces, a successful attack could result in privilege escalation to…

    Affected products in this advisory
    • Red Hat OpenShift AI 3.4
    • Red Hat OpenShift AI (RHOAI)
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • rhoai/odh-maas-api-rhel9:1787153683
    • RHSA-2026:60520
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery