A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 21:17
Updated : 2026-08-14 19:07
NVD link : CVE-2026-16456
Mitre link : CVE-2026-16456
CVE.ORG link : CVE-2026-16456
JSON object : View
Products Affected
No product.
CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
