CVE-2026-16745
Red Hat · Red Hat OpenShift AI (RHOAI)
A flaw in the odh-dashboard component of Red Hat OpenShift AI allows for an origin validation error, which may be exploited by an authenticated user to compromise system integrity.
Executive summary
A critical vulnerability in the Red Hat OpenShift AI dashboard component permits authenticated users to perform unauthorized actions due to improper origin validation.
Vulnerability
This issue is classified as an origin validation error (CWE-346), occurring within the odh-dashboard web console, allowing an authenticated attacker to potentially perform unauthorized operations.
Business impact
With a CVSS score of 8.8, this vulnerability represents a severe threat to the security posture of AI environments. Exploitation could lead to full compromise of the dashboard component, potentially allowing an attacker to manipulate AI models, access sensitive data, or disrupt machine learning workflows.
Remediation
Immediate Action: Consult the Red Hat security advisory at https://access.redhat.com/security/cve/CVE-2026-16745 and apply the latest security updates provided by the vendor.
Proactive Monitoring: Monitor access logs for the odh-dashboard for suspicious activity or anomalous requests originating from authenticated user accounts.
Compensating Controls: Implement strict network segmentation and restrict access to the dashboard web console to trusted administrative networks only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the sensitive nature of AI infrastructure, it is imperative to apply official patches as soon as they are made available by Red Hat. Administrators should review all active sessions and user permissions to limit exposure until the patch is deployed.