CVE-2026-18621
Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypassing all v2 security hardening
Record summary
CVE-2026-18621 has a selected CVSS score of 7.6 (high).
Description
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 11, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 16| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |
Default status: unknown | CVE List | Version data not supplied | |