CVE 9.9 CRITICAL

Openshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster admin_CVE-2025-10725

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it.

Basic Information

ID CVE-2025-10725
Source redhat
Published Sep 30, 2025 at 17:47

Affected Product

Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.