CVE-2025-10725 - CVE House
Back to Database
Status published Critical CVE-2025-10725

Openshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster admin

Vulnerability Description

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10725

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Jon Weiser (Red Hat), Oleg Sushchenko (Red Hat), and Raul Bringas (Red Hat).

Affected Vendor

opendatahub-io

View all reports →

Affected Software

opendatahub-operator, Red Hat OpenShift AI 2.16, Red Hat OpenShift AI 2.19, Red Hat OpenShift AI 2.21, Red Hat OpenShift AI 2.22, Red Hat OpenShift AI 2.24
Vulnerable Versions:
0, sha256:cebc8815e03b772343b15d0a7dce8fad6fcc71dd437d871db5a3691472350803, sha256:43a8904396e55074ffb1afcfcd8fe6db0edcbc918a8ff8301b6b0920aea7eabf, sha256:db339d2d4f86af4efa695ef193d19e26b25fec80017fa2780833a4cd944e383b, sha256:dccc7c6cf920da7ffeadbad42f5727f2d58d54ceef399ac98441345d06ff10c4, sha256:12c1d1066e75951aad1d333bcbc1675ba7a795b57744294c23decec1655709c7

Timeline

Official Publish: September 30th, 2025
Last Modified: December 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)