CVE-2026-5483 is a critical vulnerability in the odh-dashboard component of Red Hat OpenShift AI that exposes Kubernetes Service Account tokens through a vulnerable NodeJS endpoint, potentially allowing attackers to gain unauthorized access to Kubernetes resources and cluster infrastructure. The vulnerability carries a CVSS score of 9.9 (CRITICAL) and can be exploited by authenticated attackers with low complexity over the network. The attack requires low privileges and no user interaction, resulting in high impact across confidentiality, integrity, and availability of affected systems. The vulnerability affects the entire Kubernetes cluster due to its wide scope of potential compromise. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.0006 indicates relatively low probability of exploitation compared to the broader vulnerability landscape, though the critical severity rating warrants immediate patching efforts. Organizations running Red Hat OpenShift AI should prioritize updating the odh-dashboard component to remediate this token disclosure vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.16, < 2.16.4CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:* | ||
>= 2.25, < 2.25.4CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_ai:3.2:*:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_ai:3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.