CVE-2026-1462

high Red Hat
CVSS v3 Base Score
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
High
Published: April 13, 2026 (31 days ago)
Last Modified: April 13, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the `keras` package. This vulnerability allows an attacker to execute unauthorized code on a victim's system. It occurs when a victim loads a specially crafted `.keras` model, even if the `safe_mode` security feature is active. The issue arises because the `keras` package can unconditionally load external TensorFlow SavedModels without sufficient validation, thereby bypassing the intended security protections and leading to arbitrary code execution.

CWE

CWE-502

Affected Products

Red Hat OpenShift AI (RHOAI)

References