CVE-2026-16456

Summary

A flaw was found in the odh-model-controller. An authenticated user with permissions to create custom resources can exploit a vulnerability in the loadSecret function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat OpenShift AI 2.251785187158 < *unaffected
Red HatRed Hat OpenShift AI 3.31785189333 < *unaffected
Red HatRed Hat OpenShift AI 3.41784950479 < *unaffected

Weaknesses

  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References