Junglewise Threat Intelligence

CVE-2026-47237: Kubeflow Community Distribution authorization token theft via Istio permissions

CVE-2026-47237 · Severity: high · CVSS 8 · Published 2026-07-21

Executive brief

Kubeflow Community Distribution is a platform used to deploy and manage machine learning workflows on Kubernetes clusters. A security flaw in its default configuration allows an attacker with basic user access to steal the authentication tokens of other users, including administrators. By intercepting these tokens, an attacker can take over accounts, access sensitive research data, and manipulate machine learning pipelines or notebooks.

Technical details

The vulnerability stems from incorrect privilege assignment (CWE-266) where the 'default-editor' service account in Kubeflow namespaces is granted broad permissions on the 'networking.istio.io' API group. This allows an attacker with 'kubeflow-edit' or 'Contributor' roles to create Istio VirtualServices that override existing paths on the Kubeflow gateway (e.g., hijacking the favicon or dashboard resources). By redirecting these requests to an attacker-controlled pod, the attacker can log session cookies. To bypass default AuthorizationPolicies, the attacker can use wildcards to add victim domains to their own namespace's contributor list. The issue is fixed in version 26.03-rc.1 and via pull request #3043.

Affected products

  • kubeflow community-distribution < 26.03-rc.1
  • kubeflow manifests <= 1.9.1

Timeline

  • 2025-03-08: patched: Fix merged via PR #3043
  • 2026-05-19: advisory: GHSA published
  • 2026-07-21: disclosed: CVE published to NVD

References