CVE-2026-5483
EUVD-2026-2154710.04.2026, 18:16
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | openshift_ai | 2.16 ≤ 𝑥 < 2.16.4 |
| redhat | openshift_ai | 2.25 ≤ 𝑥 < 2.25.4 |
| redhat | openshift_ai | 3.2 |
| redhat | openshift_ai | 3.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.16 | 1775230902 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1775234711 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.2 | 1775523049 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1775239958 ≤ 𝑥 < * | ADP |
Common Weakness Enumeration
References