Information Disclosure Vulnerability in ODH Model Controller by Red Hat
CVE-2026-16456

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-16456?

A vulnerability has been identified within the ODH Model Controller that affects the handling of user inputs in the loadSecret function. Authenticated users with the ability to create custom resources can exploit this flaw, potentially allowing the improper reading of sensitive API keys and cloud credentials from other namespaces. This lack of validation opens up pathways for information disclosure, posing significant risks to the security of the entire system.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.