6.5
CVE-2026-16456
- EPSS 0.31%
- Veröffentlicht 10.08.2026 20:44:25
- Zuletzt bearbeitet 14.08.2026 19:07:46
- CVE-Watchlists
- Unerledigt
Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputy
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift AI 2.25
Default Statusaffected
Version
1785187158
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift AI 3.3
Default Statusaffected
Version
1785189333
Version <
*
Status
unaffected
HerstellerRed Hat
≫
Produkt
Red Hat OpenShift AI 3.4
Default Statusaffected
Version
1784950479
Version <
*
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.234 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
https://access.redhat.com/security/cve/CVE-2026-16456
https://bugzilla.redhat.com/show_bug.cgi?id=2503159
https://access.redhat.com/errata/RHSA-2026:53263
https://access.redhat.com/errata/RHSA-2026:53261
https://access.redhat.com/errata/RHSA-2026:53262