A flaw was found in the RHOAI training-operator. This...
High severity
Unreviewed
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 11, 2026
Description
Published by the National Vulnerability Database
Aug 10, 2026
Published to the GitHub Advisory Database
Aug 10, 2026
Last updated
Aug 11, 2026
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potentially execute arbitrary code remotely. This issue arises from the aggregation of training job permissions onto native Kubernetes edit and admin ClusterRoles, coupled with unrestricted PodTemplateSpec passthrough.
References