VYPR

Odh Dashboard

by Red Hat

CVEs (4)

  • CVE-2026-18950HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged…

  • CVE-2026-18949HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level,…

  • CVE-2026-16745HigJul 23, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker…

  • CVE-2026-5483HigApr 10, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain…