Vulnerability  ·  2026-04-12

Red Hat OpenShift AI Token Disclosure (CVE-2026-5483)

VulnerabilityHigh impactCVE-2026-5483
Kubernetes Service Account token disclosure via NodeJS endpoint in odh-dashboard component of Red Hat OpenShift AI. CVSS 8.5. Allows unauthenticated access to Kubernetes resources and potential cluster compromise.
Unauthenticated access to an exposed API endpoint in odh-dashboard leaks Kubernetes Service Account tokens, enabling lateral movement within OpenShift clusters.
Red Hat OpenShift AI deployments using odh-dashboard component.
Apply Red Hat security patch immediately. Review and rotate exposed Kubernetes Service Account tokens. Audit cluster access logs for suspicious activity.
Sources
TheHackerWire - CVE-2026-5483 Red Hat OpenShift AI
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →