CVE-2026-14450 CRITICAL

CVE-2026-14450: Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication

Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Weakness CWE-290
Published August 10, 2026
Last update August 11, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive model access configuration.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 11, 2026 Record updated

Related vulnerabilities

04Related CVE