AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18949

HIGH · CVSS 8.8 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the odh-dashboard allows attackers with access to the Service Account token to exploit excessive permissions, enabling privilege escalation to cluster-administrator level. This can lead to unauthorized access to sensitive data, including credentials and keys, as well as the potential disruption of multi-tenant isolation. Organizations using odh-dashboard should prioritize addressing this issue to safeguard their clusters and sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18949
Severity
HIGH
CVSS
8.8
EPSS
0.41%

Original NVD Description

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.