A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubernetes resources.
registry.redhat.io/rhoai/odh Rocky
Fixed in: operator-bundle@sha256:8a258b61ff3fdb4ad135e4324f855f70ec63fadb3cae54a116be028bc2663768_amd64 RHSA-2026:7397 Fixed in: dashboard-rhel9@sha256:14ee2bbd445b8a988c487d4b4a7b02ff9afe1c07034b4bba073a5a8263e3293e_amd64 RHSA-2026:7403 Fixed in: operator-bundle@sha256:870db31000afe7c68f45496b0bfcce367f48e2160bcf2af96d1802444a4352b6_amd64 RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:b513ba56ed37c886cc260cbda44b7d6a6252613be325791e8bec5d7eecb37f36_ppc64le RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:619311c040337633adf2da2a8e7ad238fbb3d0a82708c5768a41adaf7743e8a0_s390x RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:ee2fb85ca65d521e419cc7b1d0e412e71b15643c7ed6efecd9ae34a484f3f728_arm64 RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:8b94c25390d72d5b582a5a9568dcef6be601e282f38d5c887f07ae0ef1080ab6_amd64 RHSA-2026:7398 Fixed in: operator-bundle@sha256:676fc63f7dda260ac2e2491f7600571941f4a04376d2682ff8fc91acf0790d8e_amd64 RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:e0c4fd0fd200365c2dc9fe7210329280109a71596dcc4b21bda0c6648720c1ab_ppc64le RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:15ee3fb5fedf759e82c8de8020da1931c9de8138737f1cc7cf6622847a52887f_s390x RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:8872a4fc3f2b8655d81aa2a07b3e05d37191cedeec3b8fedd1c2eb33d2498ffa_arm64 RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:831be237f3b4f87d736f0f89a74f8966a565d18a496187991f820771a21695fb_amd64 RHSA-2026:7404 Fixed in: operator-bundle@sha256:099054fa7d040c2a57183e400b35c1fe67350027e638c8187e4d1ab639495f7c_amd64 RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:0bdb9912d41d799b0237fe75f3fdc843983ab4ebfe6b5a47f7d4a00a642c72cd_ppc64le RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:cea6553e74c669e4319ce1b952360d1611e11be450d237afee3ac3d4052580b3_s390x RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:8b703a2f7495c83bb632ed3cb4ebad519ea5cf10194257fae5c4509543df681d_arm64 RHSA-2026:7404 Fixed in: dashboard-rhel8@sha256:0a983da3de4ce816435e23da23c4b6f373008aaf2df2b9820bdcc77a9a110341_amd64 RHSA-2026:7397 registry.redhat.io/rhoai/odh Red Hat / RHEL
Fixed in: dashboard-rhel9@sha256:14ee2bbd445b8a988c487d4b4a7b02ff9afe1c07034b4bba073a5a8263e3293e_amd64 RHSA-2026:7403 Fixed in: operator-bundle@sha256:870db31000afe7c68f45496b0bfcce367f48e2160bcf2af96d1802444a4352b6_amd64 RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:b513ba56ed37c886cc260cbda44b7d6a6252613be325791e8bec5d7eecb37f36_ppc64le RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:619311c040337633adf2da2a8e7ad238fbb3d0a82708c5768a41adaf7743e8a0_s390x RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:ee2fb85ca65d521e419cc7b1d0e412e71b15643c7ed6efecd9ae34a484f3f728_arm64 RHSA-2026:7403 Fixed in: dashboard-rhel9@sha256:8b94c25390d72d5b582a5a9568dcef6be601e282f38d5c887f07ae0ef1080ab6_amd64 RHSA-2026:7398 Fixed in: operator-bundle@sha256:676fc63f7dda260ac2e2491f7600571941f4a04376d2682ff8fc91acf0790d8e_amd64 RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:e0c4fd0fd200365c2dc9fe7210329280109a71596dcc4b21bda0c6648720c1ab_ppc64le RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:15ee3fb5fedf759e82c8de8020da1931c9de8138737f1cc7cf6622847a52887f_s390x RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:8872a4fc3f2b8655d81aa2a07b3e05d37191cedeec3b8fedd1c2eb33d2498ffa_arm64 RHSA-2026:7398 Fixed in: dashboard-rhel9@sha256:831be237f3b4f87d736f0f89a74f8966a565d18a496187991f820771a21695fb_amd64 RHSA-2026:7404 Fixed in: operator-bundle@sha256:099054fa7d040c2a57183e400b35c1fe67350027e638c8187e4d1ab639495f7c_amd64 RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:0bdb9912d41d799b0237fe75f3fdc843983ab4ebfe6b5a47f7d4a00a642c72cd_ppc64le RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:cea6553e74c669e4319ce1b952360d1611e11be450d237afee3ac3d4052580b3_s390x RHSA-2026:7404 Fixed in: dashboard-rhel9@sha256:8b703a2f7495c83bb632ed3cb4ebad519ea5cf10194257fae5c4509543df681d_arm64 RHSA-2026:7404 Fixed in: dashboard-rhel8@sha256:0a983da3de4ce816435e23da23c4b6f373008aaf2df2b9820bdcc77a9a110341_amd64 RHSA-2026:7397 Fixed in: operator-bundle@sha256:8a258b61ff3fdb4ad135e4324f855f70ec63fadb3cae54a116be028bc2663768_amd64 RHSA-2026:7397 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Changed
Impact
Confidentiality High
Integrity High
Availability High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
0.49% probability of exploitation in 30 days
39th percentile
Low risk: more likely to be exploited than 39% of all known CVEs.
Other CWE-201 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2026-5483 Markdown
[](https://tridentstack.com/cve/CVE-2026-5483)HTML
<a href="https://tridentstack.com/cve/CVE-2026-5483"><img src="https://tridentstack.com/cve/badge/CVE-2026-5483.svg" alt="CVE-2026-5483"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-15.