PULSE
LIVE50signals / 24h
FEED
ransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Servicesransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Services
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-16745

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious

CVSS

8.8

High

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-346

EPSS · 30d

Not enough EPSS history yet.

Technical description

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-133218.6 HIG
17.4%
5The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.20h
CVE-2026-163997.5 HIG
5.5%
2Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.20h
CVE-2026-163987.5 HIG
5.5%
2Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.20h
CVE-2026-163879.8 CRI
12.3%
4Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.20h
CVE-2026-163819.1 CRI
9.4%
3Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.20h
CVE-2026-163759.8 CRI
13.0%
4Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.20h