CVE detail
CVE-2026-18621
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:53262access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 10, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53261access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 10, 2026, 9:17 PM - https://access.redhat.com/errata/RHSA-2026:53263access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 10, 2026, 9:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2510327bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comAug 10, 2026, 9:17 PM - https://access.redhat.com/security/cve/CVE-2026-18621access.redhat.com
No excerpt available.
Exploitaccess.redhat.comAug 10, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19928CVSS 2.1 · Low
A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the c…
- CVE-2026-19918CVSS 2.1 · Low
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulat…
- CVE-2026-19893CVSS 2.3 · Low
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorr…
- CVE-2026-19841CVSS 2.3 · Low
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect defa…
- CVE-2026-19835CVSS 2.0 · Low
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such man…
- CVE-2026-72826CVSS 9.3 · Critical
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target…