Database/Control plane, storage & DevOps

Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlay
Impact
The RHOAI overlay aggregates trainjobs create/update/delete into Kubernetes' built-in edit ClusterRole, so every namespace editor silently gains full control over training jobs. Chained with the companion flaw that allows arbitrary pod configuration in a TrainJob, a tenant with routine edit rights escalates to arbitrary code execution on the GPU nodes their jobs land on.
Who can reach it
Any principal bound to the standard edit ClusterRole in a namespace where the training operator is installed - a very common default for application teams.
What to do
Apply the Red Hat OpenShift AI errata (RHSA-2026:53262/53263). Independently, audit which ClusterRoles aggregate trainjobs verbs in your own overlays and split TrainJob management into a dedicated role instead of folding it into edit.
References
Related entries
- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentialsCVE-2026-22049 · NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID)High
- Jenkins: symlinks in tar archives let a job or agent write files anywhere the controller canCVE-2026-33001 · Jenkins controller (.tar/.tar.gz extraction, symlink handling)High
- Apache ActiveMQ: Improper input validation and code injection in the brokerCVE-2026-34197 · Apache ActiveMQHigh
- Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASHCVE-2026-3821 · Supermicro SMASH service (X14DBG-DAP, X14DBI)High
- Ceph RGW: unauthenticated STS token encryption lets any token holder bit-flip themselves to RGW adminCVE-2026-39944 · Ceph RADOS Gateway (STS session token AES-128-CBC handler)High
- MinIO (S3 API, Snowball auto-extract): The Snowball auto-extract path skips signature verification entirely, so anCVE-2026-40344 · MinIO (S3 API, Snowball auto-extract)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.