Changeflow GovPing Data Privacy & Cybersecurity Red Hat OpenShift AI Vulnerability Enables Info...
Urgent Guidance Amended Final

Red Hat OpenShift AI Vulnerability Enables Information Disclosure and Privilege Escalation

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published
Detected
Email

Summary

CERT-Bund issued a security advisory regarding a vulnerability in Red Hat OpenShift AI (affecting versions 2.16.4, 2.25.4, 3.3.1, and 3.2). The vulnerability, with a CVSS Base Score of 8.5 (high) and Temporal Score of 7.4 (high), allows a remote, authenticated attacker to exploit the flaw to disclose confidential information and potentially escalate privileges. Mitigation measures are available.

What changed

CERT-Bund published a security advisory identifying a high-severity vulnerability in Red Hat OpenShift AI across four specific versions (2.16.4, 2.25.4, 3.3.1, and 3.2). The vulnerability enables remote authenticated attackers to disclose confidential information and potentially escalate their privileges. The CVSS score of 8.5 reflects high severity with a temporal degradation to 7.4.

Organizations using affected Red Hat OpenShift AI versions should prioritize applying available mitigations, reviewing systems for signs of compromise, and monitoring for official patches. The vulnerability affects Unix-based operating systems and represents a significant risk to cloud platform deployments using this PaaS solution.

What to do next

  1. Apply available mitigation measures for Red Hat OpenShift AI vulnerability
  2. Review systems for indicators of exploitation
  3. Monitor for CVE updates and patches

Archived snapshot

Apr 14, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

[WID-SEC-2026-1056] Red Hat OpenShift AI: Schwachstelle ermöglicht Offenlegung von Informationen und Privilegieneskalation CVSS Base Score 8.5 (hoch) CVSS Temporal Score 7.4 (hoch) Remoteangriff ja Datum 12.04.2026 Stand 13.04.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • UNIX

Produktbeschreibung

Red Hat OpenShift ist eine "Platform as a Service" (PaaS) Lösung zur Bereitstellung von Applikationen in der Cloud.

Produkte

12.04.2026
- Red Hat OpenShift AI 2.16.4

  • Red Hat OpenShift AI 2.25.4

  • Red Hat OpenShift AI 3.3.1

  • Red Hat OpenShift AI 3.2

Angriff

Angriff

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift AI ausnutzen, um vertrauliche Informationen offenzulegen und so möglicherweise seine Berechtigungen zu erweitern. CVE Informationen Versionshistorie Feedback zum Advisory geben

Get daily alerts for CERT-Bund Security Advisories

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CERT-Bund
Published
April 12th, 2026
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-1056

Who this affects

Applies to
Technology companies Manufacturers
Industry sector
5112 Software & Technology
Activity scope
Vulnerability management Patch management Cloud platform security
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Information Security Cloud Computing

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!