CVE-2025-10725: Openshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to cluster admin

Published Sep 19, 2025
·
Updated

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it.

Other sources

OpenShift AI includes a ClusterRole named kueue-batch-user-role that is incorrectly bound to the system:authenticated group. This grants any authenticated entity, including low-privileged service accounts for user workbenches, the permission to create OpenShift Jobs in any namespace. An attacker can abuse this permission to schedule a malicious Job in a privileged namespace (e.g., openshift-apiserver-operator), configuring it to run with a high-privilege ServiceAccount. The Job can then exfiltrate the ServiceAccount token, allowing the attacker to progressively pivot and compromise more powerful accounts, ultimately achieving root access on cluster master nodes and leading to a full cluster takeover. Impact

A low-privileged attacker with access to an authenticated account, such as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the cluster's confidentiality, integrity, and availability. The attacker can steal sensitive data, disrupt all services, and take control of the underlying infrastructure, leading to a total breach of the platform and all applications hosted on it. Recommendations

Remove the ClusterRoleBinding that associates the kueue-batch-user-role with the system:authenticated group. The permission to create jobs should be granted on a more granular, as-needed basis to specific users or groups, adhering to the principle of least privilege. Avoid granting broad permissions to system-level groups. References

OWASP Top 10: A01:2021 – Broken Access Control: https://owasp.org/Top10/A012021-BrokenAccessControl/

OpenShift Documentation: Using RBAC to define and apply permissions: https://docs.openshift.com/container-platform/latest/authentication/using-rbac.html

Red Hat

Affected Software

1 affected component
Red Hat Openshift AI Service

Event History

Sep 19, 2025
Data Sourced
via Red Hat·08:46 AM
DescriptionSeverityAffected Software
Sep 30, 2025
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Oct 1, 2025
News Published
via The Register·07:35 PM
News Published
via The Register·07:38 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-10725?

CVE-2025-10725 is considered a high severity vulnerability due to its potential for privilege escalation.

2

How do I fix CVE-2025-10725?

To fix CVE-2025-10725, administrators should immediately apply the patches provided by Red Hat for the OpenShift AI Service.

3

Who is affected by CVE-2025-10725?

CVE-2025-10725 affects users with low-privileged authenticated accounts in Red Hat OpenShift AI.

4

What can an attacker do if they exploit CVE-2025-10725?

An attacker exploiting CVE-2025-10725 can escalate their privileges and gain full administrator access to the OpenShift cluster.

5

What types of accounts are vulnerable to CVE-2025-10725?

Low-privileged accounts, such as those of data scientists using Jupyter notebooks, are vulnerable to CVE-2025-10725.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203