Last seen June 16, 2026

OpenShift AI overly permissive ClusterRole Vulnerability

This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable

Why This Matters

Publisher reporting describes a security event affecting and. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether and is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Jun 16, 2026 12:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSAnthropicGitHubGoogleMetaMicrosoft

Authoritative Intelligence

CVE CVE-2025-10725 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Oct 01, 2025 05:30

    BugSkan first recorded this incident.

  • Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover - The Hacker News
    Oct 01, 2025 05:30

    thehackernews.com ยท Vulnerability

  • LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers - The Hacker News
    Jun 15, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Critical LiteLLM Vulnerability Chain Enables Remote Code Execution and Full AI Gateway Server Takeover (CVE-2026-42271, CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) - Rescana
    Jun 16, 2026 12:30

    news.google.com ยท Data Leak

  • This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data - Mashable
    Jun 16, 2026 12:30

    news.google.com ยท Malware

  • Latest observed development
    Jun 16, 2026 12:30

    Most recent source or update associated with this incident.

Sources

Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover - The Hacker News

thehackernews.com ยท Oct 01, 2025 05:30

A critical vulnerability, CVE-2025-10725 (CVSS 9.9), allows authenticated, low-privileged attackers to escalate privileges to a full cluster administrator in Red Hat OpenShift AI. This flaw, due to an overly permissive ClusterRole, enables abuse of OpenShift Jobs to exfiltrate high-privilege ServiceAccount tokens, leading to a complete takeover of the hybrid cloud infrastructure.

Open publisher source
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers - The Hacker News

thehackernews.com ยท Jun 15, 2026 05:30

A critical chain of three vulnerabilities (CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) in LiteLLM allows a low-privilege internal user to bypass authorization, escalate privileges to full proxy admin, and achieve remote code execution (CVSS 9.9). This enables exfiltration of sensitive data like AI provider keys and credentials, and the ability to forge AI model responses in transit, requiring immediate upgrade to v1.83.14-stable or later.

Open publisher source
Critical LiteLLM Vulnerability Chain Enables Remote Code Execution and Full AI Gateway Server Takeover (CVE-2026-42271, CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) - Rescana

news.google.com ยท Jun 16, 2026 12:30

Critical LiteLLM Vulnerability Chain Enables Remote Code Execution and Full AI Gateway Server Takeover (CVE-2026-42271, CVE-2026-47101, CVE-2026-47102, CVE-2026-40217) Rescana

Open publisher source
This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data - Mashable

news.google.com ยท Jun 16, 2026 12:30

This Copilot vulnerability could expose emails, 2FA codes, and other sensitive data Mashable

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence