CVE Explorer
CVE-2026-47237
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The attacker needs a va
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"community-distribution","vendor":"kubeflow","versions":[{"status":"affected","version":"< 26.03-rc.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-266","description":"CWE-266: Incorrect Privilege Assignment","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/kubeflow/community-distribution/commit/31b2411dda319bfeae8686ecdf3a39436ec32ce2","tags":["x_refsource_MISC"],"url":"https://github.com/kubeflow/community-distribution/commit/31b2411dda319bfeae8686ecdf3a39436ec32ce2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/references/2
{"name":"https://github.com/kubeflow/community-distribution/pull/3043","tags":["x_refsource_MISC"],"url":"https://github.com/kubeflow/community-distribution/pull/3043"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/references/1
{"name":"https://github.com/kubeflow/community-distribution/security/advisories/GHSA-v824-8gxh-pgjw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/kubeflow/community-distribution/security/advisories/GHSA-v824-8gxh-pgjw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/kubeflow/community-distribution/security/advisories/GHSA-v824-8gxh-pgjw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:19937fb1b661a63bd389ac023c54e73f2c25a04e10d7b3907ee759ed394450db · sha256:feb8bbd742eaa600… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.