CVE-2026-18950
Received Received - Intake

Privilege Escalation in odh-dashboard via RoleBinding Manipulation

Vulnerability report for CVE-2026-18950, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
odh-dashboard odh-dashboard *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in odh-dashboard where an authenticated user can exploit improper validation of the RoleBindings' roleRef field. This allows specifying arbitrary roles, including highly privileged ones like cluster-admin, leading to privilege escalation and unauthorized elevated access within their namespace and potential persistent system control.

Impact Analysis

An attacker with dashboard access could escalate privileges to gain control over their namespace or the entire system. This may allow unauthorized data access, modification, or disruption of services, depending on the granted permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating compliance requirements such as GDPR's data protection principles or HIPAA's access controls. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update odh-dashboard to the latest version that patches the RoleBinding validation flaw. Review existing RoleBindings for unauthorized or highly privileged roles like cluster-admin. Restrict dashboard user permissions to the minimum required. Monitor for suspicious activity or unauthorized privilege changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18950. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart