info: name: kubeflow cve: CVE-2026-47237 summary: Kubeflow Community Distribution - Authorization Token Stealing via Incorrect Privilege Assignment details: Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The attacker needs a valid Kubeflow account but can steal tokens from any other user including admins. This vulnerability is due to incorrect privilege assignment (CWE-266). cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity: HIGH security_advise: Upgrade Kubeflow Community Distribution to version 26.03-rc.1 or later. If immediate upgrade is not possible, review and restrict network access to Kubeflow APIs and consider implementing additional authentication middleware to prevent token theft. rule: version < "26.03-rc.1" references: - https://github.com/kubeflow/community-distribution/commit/31b2411dda319bfeae8686ecdf3a39436ec32ce2 - https://github.com/kubeflow/community-distribution/pull/3043 - https://github.com/kubeflow/community-distribution/security/advisories/GHSA-v824-8gxh-pgjw