Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16456

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the odh-model-controller. An authenticated user with permissions to create custom resources can exploit a vulnerability in the loadSecret function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.

Отчет

Important: This confused deputy vulnerability in Red Hat OpenShift AI allows an authenticated user to exfiltrate secrets across namespaces. The odh-model-controller, with its cluster-wide secret access, processes user-controlled input without validating the secret's namespace, enabling an attacker to read sensitive information from other namespaces, including high-value Red Hat OpenShift AI-managed secrets.

Дополнительная информация

Статус:

Important
Дефект:
CWE-441
https://bugzilla.redhat.com/show_bug.cgi?id=2503159odh-model-controller: odh-model-controller: Cross-namespace secret read via NIM Account CRD confused deputy

EPSS

Процентиль: 24%
0.00309
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
7 дней назад

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.

CVSS3: 6.5
github
7 дней назад

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.

EPSS

Процентиль: 24%
0.00309
Низкий

6.5 Medium

CVSS3