Dismissed
(no matching packages found)
Permalink
CVE-2026-18949
8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
References
Affected products
rhoai/odh-dashboard-rhel9
rhoai/odh-mod-arch-maas-rhel9
rhoai/odh-mod-arch-automl-rhel9
rhoai/odh-mod-arch-gen-ai-rhel9
rhoai/odh-mod-arch-mlflow-rhel9
rhoai/odh-mod-arch-autorag-rhel9
rhoai/odh-mod-arch-eval-hub-rhel9
rhoai/odh-mod-arch-model-registry-rhel9