CVE-2026-86332
Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).
| CWE | CWE-862 |
| Vendor | red hat |
| Product | red hat openshift ai (rhoai) |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Get instant alerts for red hat red hat openshift ai (rhoai)
Be the first to know when new medium vulnerabilities affecting red hat red hat openshift ai (rhoai) are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N