Impact
A misconfiguration in Kubeflow Community Distribution releases before 26.03-rc.1 allows any user with a Kubeflow‑edit role to exploit overly permissive Istio permissions and capture the bearer token used by the Kubeflow UI or APIs. With that token an attacker can assume the victim’s identity and access all data and operations performed under that account. The weakness, identified as a privilege‑escalation flaw, provides a path to full account compromise.
Affected Systems
The vulnerable software is the Kubeflow Community Distribution package deployed on Kubernetes clusters. Versions prior to 26.03-rc.1, especially those built from official manifests or other packaged distributions, are susceptible. The vulnerability arises when Automatic Profile Creation is enabled, which grants the kubeflow-edit (Contributor) role in arbitrary namespaces by default.
Risk and Exploitability
The CVSS score of 8 indicates high severity, and the EPSS score of less than 1% suggests that exploitation is currently unlikely but still possible. Because the attack requires only a valid user with contributor access, the attack vector is likely through legitimate user interactions with the Kubeflow UI or APIs. The vulnerability is not listed in the CISA KEV catalog, which limits current public exploit evidence, but the combination of high impact and low exploit probability warrants prompt remediation.
OpenCVE Enrichment