CVE-2026-16745: Origin Validation Error in Red Hat Red Hat OpenShift AI 2.25
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
AI Analysis
Technical Summary
CVE-2026-16745 is an origin validation error in the odh-dashboard web console component of Red Hat OpenShift AI. The backend binds to 0.0.0.0:8080 and trusts the x-forwarded-access-token header without validating the origin, allowing any pod in the cluster to impersonate users by supplying arbitrary tokens. This bypasses the intended kube-rbac-proxy authentication, enabling unauthorized access to the Kubernetes API with high impact on confidentiality, integrity, and availability. The vulnerability affects RHOAI versions 2.25, 3.3, and 3.4. Red Hat has released updated images and a fixed version 3.3.6 to address this issue.
Potential Impact
An attacker with access to any pod within the cluster can bypass authentication mechanisms and impersonate any user by providing arbitrary access tokens. This leads to unauthorized access to the Kubernetes API, which can result in arbitrary code execution, privilege escalation, and disclosure of sensitive information. The CVSS v3.1 score is 8.8 (High), reflecting the critical nature of the impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released a fixed version, Red Hat OpenShift AI 3.3.6, which addresses this vulnerability. Users are strongly advised to upgrade to this version following the official Red Hat documentation for cluster upgrades. No alternative mitigations are specified in the advisory. Patch status is official-fix and available.
CVE-2026-16745: Origin Validation Error in Red Hat Red Hat OpenShift AI 2.25
Description
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
CVSS v3.1
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16745 is an origin validation error in the odh-dashboard web console component of Red Hat OpenShift AI. The backend binds to 0.0.0.0:8080 and trusts the x-forwarded-access-token header without validating the origin, allowing any pod in the cluster to impersonate users by supplying arbitrary tokens. This bypasses the intended kube-rbac-proxy authentication, enabling unauthorized access to the Kubernetes API with high impact on confidentiality, integrity, and availability. The vulnerability affects RHOAI versions 2.25, 3.3, and 3.4. Red Hat has released updated images and a fixed version 3.3.6 to address this issue.
Potential Impact
An attacker with access to any pod within the cluster can bypass authentication mechanisms and impersonate any user by providing arbitrary access tokens. This leads to unauthorized access to the Kubernetes API, which can result in arbitrary code execution, privilege escalation, and disclosure of sensitive information. The CVSS v3.1 score is 8.8 (High), reflecting the critical nature of the impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released a fixed version, Red Hat OpenShift AI 3.3.6, which addresses this vulnerability. Users are strongly advised to upgrade to this version following the official Red Hat documentation for cluster upgrades. No alternative mitigations are specified in the advisory. Patch status is official-fix and available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-23T10:24:31.723Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-16745","vendor":"Red Hat"}]
Threat ID: 6a61f5fe9c2644c7f8f12ffd
Added to database: 07/23/2026, 11:07:42 UTC
Last enriched: 08/11/2026, 13:44:08 UTC
Last updated: 09/05/2026, 10:52:07 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.