Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-14450: MaaS API: Unauthorized Access via Fake User IDs
CVE-2026-14450 · published 24 days ago
Summary
The MaaS API has a security flaw that allows attackers to pretend to be a valid user and gain access to sensitive information. This can lead to unauthorized access to other users' data and the ability to control their accounts. To stay safe, update the MaaS API to the latest version, and make sure to follow security best practices to prevent similar issues in the future.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat openshift ai (rhoai) | All versions |
Original advisory text
Maas-billing: maas api: privilege escalation via forged http headers due to missing authentication
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive model access configuration.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published10 Aug 2026
Updated3 Sep 2026
First seen10 Aug 2026
Monitor software like this
Free during beta