漏洞情报聚合

CVE-2026-16745 - A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. - 漏洞详情

漏洞编号:CVE-2026-16745

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-16745

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-346

发布/更新时间:2026-07-23 / 2026-08-27

漏洞描述

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

相关链接

相关漏洞

« 返回首页