CVE-2026-5483: Red Hat Openshift Ai
Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.
Affected products
- Red Hat Openshift Ai: from 2.16, before 2.16.4 (fixed in 2.16.4); from 2.25, before 2.25.4 (fixed in 2.25.4); version 3.2 only; version 3.3 only
Published 2026-04-10. Last modified 2026-07-15.