Product
high
advisory
CVE-2026-18949: Privilege Escalation via Overly Permissive Service Account in Open Data Hub
2 TTPs 1 CVEA vulnerability in the Open Data Hub odh-dashboard allows an attacker with a compromised Service Account token to escalate to cluster-administrator privileges due to excessive RBAC permissions.
odh-dashboard
privilege-escalation
cloud-native
kubernetes
2t
1c
high
advisory
CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard
4 TTPs 1 CVEA critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.
odh-dashboard +1
cloud-security
kubernetes
authentication-bypass
privilege-escalation
arbitrary-code-execution
red-hat
4t
1c