MEDIUM 6.5 NVD

CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the `loadSecret` function. This function improperly reads the Secret namespace from user-controlled input without validation. This allows an attacker to read sensitive API keys and cloud credentials from other namespaces, leading to information disclosure.

References

Published: 2026-08-10 · Source: NVD · Feed updated: 2026-08-11
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-10 via NVD.
vulnfeed aggregates 7836 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.