PatchSiren

kubeflow CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kubeflow CVE published 2026-07-21

CVE-2026-47237

CVE-2026-47237 is a high-severity vulnerability in Kubeflow Community Distribution that allows authorization token stealing from any user of the Kubeflow UI or APIs. The vulnerability exists prior to version 26.03-rc.1 and allows an attacker to take over a user's account and access their data. The attacker needs a valid user with the 'kubeflow-edit' role or Contributor role in a random Kubeflow namespace [truncated]