CVE-2026-12482

medium Red Hat
CVSS v3 Base Score
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.3%
Exploitation probability in 30 days
Top 78% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Confidentiality
Low
Integrity
Low
Availability
None
Published: July 14, 2026 (54 days ago)
Last Modified: July 14, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in Keras. An attacker can exploit a vulnerability in the tar archive processing to bypass security validations. This allows for the creation of symbolic links (symlinks) outside of the intended directory, which could lead to unauthorized access to or modification of files on the system, or enable an attacker to navigate beyond restricted directories.

CWE

CWE-22

Affected Products

Red Hat OpenShift AI (RHOAI)

References