Junglewise Threat Intelligence

CVE-2026-16745: Red Hat OpenShift AI authentication bypass in odh-dashboard

CVE-2026-16745 · Severity: high · CVSS 8.8 · Published 2026-07-23

Vendors: Red Hat.

Executive brief

A security flaw was found in the web console of Red Hat OpenShift AI (RHOAI). Due to a configuration error, an attacker already inside the cluster can bypass security checks and impersonate any user. This could allow them to gain full control over the system, access sensitive data, or disrupt operations.

Technical details

A vulnerability exists in the odh-dashboard component of Red Hat OpenShift AI (RHOAI) due to an origin validation error (CWE-346). The dashboard backend binds to 0.0.0.0:8080 and incorrectly trusts the 'x-forwarded-access-token' HTTP header without verifying its source. While a kube-rbac-proxy sidecar is intended to handle authentication, the backend's network binding and permissive NetworkPolicies allow other pods in the cluster to communicate directly with port 8080. An attacker can send requests directly to this port with a spoofed token, allowing them to impersonate any user and perform actions against the Kubernetes API. The issue is fixed in RHOAI 3.5 by binding the backend to 127.0.0.1.

Affected products

  • Red Hat Red Hat OpenShift AI (RHOAI) 2.25, 3.3, 3.4

Timeline

  • 2026-05-27: patched: Upstream PR #7411 merged to bind backend to localhost
  • 2026-07-23: disclosed: CVE-2026-16745 published

References