CVE-2026-18621
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a
CVSS
7.6
High
EPSS
0.3%
p27
KEV
—
Exploit Today
8
0-100
Published: Aug 10, 2026 · Last modified: Aug 11, 2026 · CWE-266
Not enough EPSS history yet.
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:53261
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:53262
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:53263
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-18621
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2510327
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-64639——
———Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.5hCVE-2026-714685.3 MED—
——0A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.4hCVE-2026-154678.1 HIG30.1%
——9A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.5hCVE-2026-193817.8 HIG1.5%
——0A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-193767.3 HIG28.3%
——8A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.3dCVE-2026-193604.7 MED12.4%
——4A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.2d