Database/Control plane, storage & DevOps

Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attacker
Impact
Reflected XSS in the Kubeflow dashboard runs attacker JavaScript in a logged-in user's browser under the Kubeflow origin. The attacker acts as that user against the Kubeflow API - which for an admin means creating notebooks and pipelines and reading other namespaces' resources.
Who can reach it
An authenticated Kubeflow user who follows an attacker-crafted link, so it needs both a valid session and a click.
What to do
Upgrade Kubeflow past the fixed dashboard release and redeploy the central dashboard. Add a Content-Security-Policy at the ingress in front of Kubeflow as a standing mitigation for this class.
References
Related entries
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsCVE-2026-12910 · GitLab CE/EE (SAML SSO sign-in enforcement)Medium
- Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by adminsCVE-2026-13720 · Grafana dashboard API (grafana.app/managedBy provisioning annotations)Medium
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessCVE-2026-4398 · GitLab EE self-managed (compliance framework namespace validation)Medium
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionCVE-2026-45694 · LibreNMS (Proxmox application view, instance and vmid parameters)Medium
- Strimzi: partial Entity Operator deployments still get both operators' RBAC, over-granting the SACVE-2026-55226 · Strimzi Kafka Operator (Entity Operator ServiceAccount RBAC)Medium
- Jenkins Stapler: form binding writes public static fields, applying changes instance-wideCVE-2026-84654 · Jenkins Stapler (form data binding to public static fields)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.