A critical privilege escalation vulnerability, tracked as CVE-2025-10725, has been identified in Red Hat OpenShift AI Service. This flaw is rated with a CVSS score of 9.9, indicating its severe impact on affected systems. The vulnerability arises from an overly permissive clusterrole configuration, which allows authenticated users, such as data scientists operating standard Jupyter notebooks, to escalate their privileges to that of a full cluster administrator. Exploitation of this flaw enables attackers to gain complete control over the OpenShift AI cluster, compromising its confidentiality, integrity, and availability. Attackers leveraging this vulnerability can steal sensitive data, disrupt all hosted services, and take over the underlying infrastructure. The risk extends to all applications and workloads running on the compromised cluster, potentially leading to widespread operational and data loss. The vulnerability is remotely exploitable, meaning attackers do not require physical access to the environment. Red Hat has acknowledged the issue and released security advisories to inform customers of the risk. The flaw was publicly disclosed on September 30, 2025, and security researchers have emphasized the urgency of patching affected systems. Organizations using Red Hat OpenShift AI are strongly advised to review their clusterrole permissions and apply available patches or mitigations immediately. The vulnerability highlights the importance of least-privilege access controls in containerized and AI-driven environments. Failure to address this issue could result in attackers gaining persistent access to critical infrastructure. The incident underscores the need for continuous monitoring and timely response to privilege escalation threats in cloud-native platforms. Security teams should also audit user roles and permissions to prevent similar misconfigurations in the future. The disclosure has prompted industry-wide discussions on the security of AI and machine learning platforms. Red Hat customers are encouraged to consult official advisories and update their systems without delay to mitigate the risk of exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Alongside disclosure, Red Hat published mitigations for affected environments, including removing the binding between the kueue-batch-user-role ClusterRole and the system:authenticated group and enforcing least-privilege access controls. Security reporting urged organizations to patch quickly and investigate for possible prior compromise.
Red Hat disclosed CVE-2025-10725, a privilege-escalation flaw in OpenShift AI caused by an overly permissive ClusterRoleBinding/ClusterRole configuration. The issue could let a minimally authenticated user create jobs in arbitrary namespaces, escalate to cluster-admin, and potentially gain root access across the cluster.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.