Information Disclosure Vulnerability in ODH Model Controller by Red Hat
CVE-2026-16456
6.5MEDIUM
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-16456?
A vulnerability has been identified within the ODH Model Controller that affects the handling of user inputs in the loadSecret function. Authenticated users with the ability to create custom resources can exploit this flaw, potentially allowing the improper reading of sensitive API keys and cloud credentials from other namespaces. This lack of validation opens up pathways for information disclosure, posing significant risks to the security of the entire system.
Affected Version(s)
Red Hat OpenShift AI 2.25 1785187158
Red Hat OpenShift AI 3.3 1785189333
Red Hat OpenShift AI 3.4 1784950479