CVE-2026-16745
🟡 Monitoruj
Błąd w odh-dashboard umożliwia ominięcie uwierzytelnienia i dostęp do API Kubernetes.
CVSS
8.8
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
auth-bypass privilege-escalation rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-07-23 11:16:40 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 17:17:17 UTC |
Referencje
- https://access.redhat.com/errata/RHSA-2026:53261 (secalert@redhat.com)
- https://access.redhat.com/errata/RHSA-2026:53262 (secalert@redhat.com)
- https://access.redhat.com/errata/RHSA-2026:53263 (secalert@redhat.com)
- https://access.redhat.com/errata/RHSA-2026:60520 (secalert@redhat.com)
- https://access.redhat.com/security/cve/CVE-2026-16745 (secalert@redhat.com)
- https://bugzilla.redhat.com/show_bug.cgi?id=2506350 (secalert@redhat.com)