Auth Bypass in Red Hat ODH-Dashboard via Network Binding
CVE-2026-16745 Published on July 23, 2026
Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Vulnerability Analysis
CVE-2026-16745 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
Products Associated with CVE-2026-16745
Want to know whenever a new CVE is published for Red Hat Openshift Ai? stack.watch will email you.