OpenShift AI overly permissive ClusterRole Vulnerability
This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable
STABLE
What Happened
This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable
Why This Matters
Publisher reporting describes a security event affecting and. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether and is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Jun 16, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
Timeline
-
Incident first seen
Oct 01, 2025 05:30BugSkan first recorded this incident.
-
Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover - The Hacker News
Oct 01, 2025 05:30thehackernews.com ยท Vulnerability
-
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers - The Hacker News
Jun 15, 2026 05:30thehackernews.com ยท Vulnerability
-
Critical LiteLLM Vulnerability Chain Enables Remote Code Execution and Full AI Gateway Server Takeover (CVE-2026-42271, CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) - Rescana
Jun 16, 2026 12:30news.google.com ยท Data Leak
-
This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data - Mashable
Jun 16, 2026 12:30news.google.com ยท Malware
-
Latest observed development
Jun 16, 2026 12:30Most recent source or update associated with this incident.
Sources
thehackernews.com ยท Oct 01, 2025 05:30
A critical vulnerability, CVE-2025-10725 (CVSS 9.9), allows authenticated, low-privileged attackers to escalate privileges to a full cluster administrator in Red Hat OpenShift AI. This flaw, due to an overly permissive ClusterRole, enables abuse of OpenShift Jobs to exfiltrate high-privilege ServiceAccount tokens, leading to a complete takeover of the hybrid cloud infrastructure.
Open publisher sourcethehackernews.com ยท Jun 15, 2026 05:30
A critical chain of three vulnerabilities (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) in LiteLLM allows a low-privilege internal user to bypass authorization, escalate privileges to full proxy admin, and achieve remote code execution (CVSS 9.9). This enables exfiltration of sensitive data like AI provider keys and credentials, and the ability to forge AI model responses in transit, requiring immediate upgrade to v1.83.14-stable or later.
Open publisher sourcenews.google.com ยท Jun 16, 2026 12:30
Critical LiteLLM Vulnerability Chain Enables Remote Code Execution and Full AI Gateway Server Takeover (CVE-2026-42271, CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) Rescana
Open publisher sourcenews.google.com ยท Jun 16, 2026 12:30
This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.