Red HatCVE-2026-16745
Red Hat odh-dashboard: authentication bypass
High8.8CVE-2026-16745 · Published Jul 23, 2026 · updated Sep 8, 2026
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-346
- www.cve.org/CVERecord?id=CVE-2026-16745
- nvd.nist.gov/vuln/detail/CVE-2026-16745
- access.redhat.com/errata/RHSA-2026:53261
- access.redhat.com/errata/RHSA-2026:53262
- access.redhat.com/errata/RHSA-2026:53263
- access.redhat.com/errata/RHSA-2026:60520
- access.redhat.com/errata/RHSA-2026:65126
- access.redhat.com/security/cve/CVE-2026-16745
- bugzilla.redhat.com/show_bug.cgi?id=2506350
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Red Hat Certificate System 9: resource leak | Medium5.3 | No fix yet |
| Jul 23 | Red Hat gdk-pixbuf.: out-of-bounds read | Medium5.3 | No fix yet |
| Jul 23 | Red Hat libcupsfilters: infinite loop | High7.5 | No fix yet |
| Jul 23 | Red Hat GNU nano: information disclosure | Medium6.8 | No fix yet |
| Jul 22 | Red Hat librest: attacker could bypass PKCE protections | Medium6.8 | No fix yet |
| Jul 22 | Red Hat Directory Server 11: denial of service | Medium5.3 | No fix yet |