CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 21:17

Updated : 2026-08-14 19:07


NVD link : CVE-2026-16456

Mitre link : CVE-2026-16456

CVE.ORG link : CVE-2026-16456


JSON object : View

Products Affected

No product.

CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')