VDB
CVE-2026-16745
CVE-2026-16745
PUBLISHED
CVSS 8.8 HIGH
Reported by redhat · Published July 23, 2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785940823 |
| Red Hat | Red Hat OpenShift AI 2.25 | 1788312226 |
| Red Hat | Red Hat OpenShift AI 3.3 | 1786109683 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1786109665 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1787347991 |
| Red Hat | Red Hat OpenShift AI 2.25 | 1785940823, 1788312226, 1785940823 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1786109665, 1786109665, 1787347991 |
| Red Hat | Red Hat OpenShift AI 3.3 | 1786109683, 1786109683, 1786109683 |
| Red Hat | Red Hat OpenShift AI (RHOAI) |
Timeline
- Jul 23, 2026 CVE Published
- Jul 24, 2026 Coalition ESS Score
- Jul 25, 2026 EPSS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 8, 2026 CVE Updated
- Sep 9, 2026 EPSS Score
References
- RHSA-2026:53261 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53262 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:53263 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:60520 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:65126 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2506350 issue-trackingx_refsource_REDHAT