Red Hat OpenShift AI Vulnerability Enables Information Disclosure and Privilege Escalation
Summary
CERT-Bund issued a security advisory regarding a vulnerability in Red Hat OpenShift AI (affecting versions 2.16.4, 2.25.4, 3.3.1, and 3.2). The vulnerability, with a CVSS Base Score of 8.5 (high) and Temporal Score of 7.4 (high), allows a remote, authenticated attacker to exploit the flaw to disclose confidential information and potentially escalate privileges. Mitigation measures are available.
What changed
CERT-Bund published a security advisory identifying a high-severity vulnerability in Red Hat OpenShift AI across four specific versions (2.16.4, 2.25.4, 3.3.1, and 3.2). The vulnerability enables remote authenticated attackers to disclose confidential information and potentially escalate their privileges. The CVSS score of 8.5 reflects high severity with a temporal degradation to 7.4.
Organizations using affected Red Hat OpenShift AI versions should prioritize applying available mitigations, reviewing systems for signs of compromise, and monitoring for official patches. The vulnerability affects Unix-based operating systems and represents a significant risk to cloud platform deployments using this PaaS solution.
What to do next
- Apply available mitigation measures for Red Hat OpenShift AI vulnerability
- Review systems for indicators of exploitation
- Monitor for CVE updates and patches
Archived snapshot
Apr 14, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-1056] Red Hat OpenShift AI: Schwachstelle ermöglicht Offenlegung von Informationen und Privilegieneskalation CVSS Base Score 8.5 (hoch) CVSS Temporal Score 7.4 (hoch) Remoteangriff ja Datum 12.04.2026 Stand 13.04.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- UNIX
Produktbeschreibung
Red Hat OpenShift ist eine "Platform as a Service" (PaaS) Lösung zur Bereitstellung von Applikationen in der Cloud.
Produkte
12.04.2026
- Red Hat OpenShift AI 2.16.4
Red Hat OpenShift AI 2.25.4
Red Hat OpenShift AI 3.3.1
Red Hat OpenShift AI 3.2
Angriff
Angriff
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift AI ausnutzen, um vertrauliche Informationen offenzulegen und so möglicherweise seine Berechtigungen zu erweitern. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.