A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
History

Tue, 11 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:2.25::el9
cpe:/a:redhat:openshift_ai:3.4::el9
References

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Openshift Ai (rhoai)
CPEs cpe:/a:redhat:openshift_ai:3.3::el9
Vendors & Products Red Hat
Red Hat red Hat Openshift Ai (rhoai)
References

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 10 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like credentials and keys across the entire cluster, and disrupt multi-tenant isolation.
Title Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac management resources
First Time appeared Redhat
Redhat openshift Ai
Weaknesses CWE-250
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-08-10T20:45:00.451Z

Updated: 2026-08-11T18:39:02.666Z

Reserved: 2026-08-05T13:39:50.738Z

Link: CVE-2026-18949

cve-icon Vulnrichment

Updated: 2026-08-11T17:14:00.955Z

cve-icon NVD

Status : Received

Published: 2026-08-10T21:17:21.443

Modified: 2026-08-11T19:17:31.520

Link: CVE-2026-18949

cve-icon Redhat

Severity : Critical

Publid Date: 2026-08-10T18:53:34Z

Links: CVE-2026-18949 - Bugzilla