CVE-2026-16745
Description
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Déclaration
Important: This flaw allows for privilege escalation within the cluster by bypassing authentication. It is due to the odh-dashboard backend binding to 0.0.0.0:8080 and trusting the x-forwarded-access-token header without origin validation. This enables any pod in the cluster to impersonate users by supplying an arbitrary token, circumventing the intended kube-rbac-proxy authentication. This affects Red Hat OpenShift AI (RHOAI) versions 2.25, 3.3, and 3.4.
Détails du score du système commun d'évaluation des vulnérabilités (CVSS)
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
Répartition des scores CVSS v3
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Score de base | 8.8 | N/A | 8.8 |
| Vecteur d'attaque | Network | N/A | Network |
| Complexité de l'attaque | Low | N/A | Low |
| Privilèges requis | Low | N/A | Low |
| Interaction avec l'utilisateur | None | N/A | None |
| Champ d'application | Unchanged | N/A | Unchanged |
| Confidentialité | High | N/A | High |
| Impact sur l'intégrité | High | N/A | High |
| Impact sur la disponibilité | High | N/A | High |
Vecteur
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Comprendre la Défaillance (CWE)
Access Control,Other
Technical Impact: Gain Privileges or Assume Identity; Varies by Context
An attacker can access any functionality that is inadvertently accessible to the source.
Questions fréquemment posées
Not sure what something means? Check out our Security Glossary.
Vous souhaitez recevoir des notifications d'errata ? Signez ici.