SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16745

HIGH · CVSS 8.8 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A vulnerability in the odh-dashboard component of Red Hat OpenShift AI allows authenticated users within a Kubernetes cluster to bypass authentication and impersonate any user by exploiting incorrect network binding. This could enable attackers to gain unauthorized access to the Kubernetes API, leading to potential arbitrary code execution, privilege escalation, or information disclosure. Organizations using Kubernetes and Red Hat OpenShift AI should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16745
Severity
HIGH
CVSS
8.8
EPSS
0.27%
Kubernetes

Original NVD Description

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.