Executive brief
OpenShift AI's dashboard component exposes a critical credential management flaw that allows any logged-in user—even those without administrative privileges—to read and retrieve sensitive NVIDIA NGC API keys and image pull secrets that should be restricted to administrators only. An attacker with dashboard access can extract these shared infrastructure credentials without triggering any authorization checks, potentially compromising the organization's AI model serving infrastructure and external API integrations.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the backend-for-frontend route GET /api/nim-serving/:nimResource. The endpoint reads Kubernetes Secrets using the dashboard service account and returns the full Secret object including the .data field without verifying that the caller has admin privileges. While sibling routes for create and delete operations correctly use secureAdminRoute, the read path does not. An authenticated (but non-admin) dashboard user can exploit this over the network to retrieve NVIDIA NGC API key and NIM image pull secrets. The vulnerability requires an active dashboard session and a configured NIM Account, but no additional user interaction. A patch restricting read operations to administrators or stripping sensitive .data fields from responses is needed.
Affected products
- Red Hat OpenShift AI not specified
Timeline
- 2026-09-07: disclosed
- 2026-09-07: advisory: Red Hat advisory CVE-2026-86332