CVE-2026-47237 Details
Description
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The attacker needs a valid user with the ``kubeflow-edit`` role / Contributor role in a random Kubeflow namespace to perform this attack. This is given if _Automatic Profile Creation_ is enabled. Version 26.03-rc.1 fixes the issue.
A vulnerability exists in Kubeflow Community Distribution versions prior to 26.03-rc.1, allowing for the theft of authorization tokens from users interacting with the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. This vulnerability enables an attacker to take over the user's account and access their data. The issue arises from overly permissive Istio permissions that allow the creation of VirtualServices, which can be exploited to hijack user sessions by redirecting requests to an attacker-controlled Pod. To exploit this vulnerability, an attacker must have a valid user account with the 'kubeflow-edit' role in a Kubeflow namespace, a condition met if 'Automatic Profile Creation' is enabled.
Users can update to Kubeflow Community Distribution version 26.03-rc.1 or later, where this vulnerability has been fixed. Additionally, the permissions granted by the 'kubeflow-edit' role should be reviewed and adjusted to prevent similar vulnerabilities in the future.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |