Impact
A flaw in odh-dashboard grants its Service Account an overly broad ClusterRole that allows full control of secrets and RBAC resources. When an attacker compromises the dashboard’s Service Account token, the attacker can use these permissions to obtain all cluster secrets, keys and credentials, create new ClusterRoleBindings, and disrupt multi‑tenant isolation. The weakness corresponds to CWE‑250, leading to privilege escalation to cluster‑administrator level.
Affected Systems
Red Hat OpenShift AI (RHOAI) is the only affected product identified by the CNA. No specific version information is listed, so the vulnerability may be present in all supported releases of RHOAI.
Risk and Exploitability
The CVSS score of 8.8 points to a high‑severity vulnerability, but the EPSS score is not available, indicating no current data on exploitation likelihood. The issue is not listed in the CISA KEV catalog. Exploitation requires that an attacker can obtain the odh‑dashboard Service Account token—typically through internal compromise or misconfiguration—after which they can leverage the ClusterRole to read and manipulate cluster‑wide secrets and RBAC settings. The attack vector therefore relies on internal access and permission abuse, resulting in cluster‑wide privilege escalation and data exposure.
OpenCVE Enrichment