CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14450

criticalCVSS 9.9covered by 1 sourcefirst seen 2026-08-10
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically X-MaaS-Username and X-MaaS-Group, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized access and escalate privileges. The concrete consequences include the ability to mint Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive model access configuration.

⚡ Watch CVE-2026-14450

Get an email if CVE-2026-14450 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-14450

CVE.org record

Embed the live status

CVE-2026-14450 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14450 status](https://www.csirts.com/badge/CVE-2026-14450)](https://www.csirts.com/cve/CVE-2026-14450)