---
id: CVE-2026-18950
title: A flaw was found in odh-dashboard
summary: >-
  A flaw was found in odh-dashboard. An authenticated user of the dashboard can
  exploit a vulnerability related to how RoleBindings are created. The system
  does not properly validate the `roleRef` field, allowing a user to specify an
  arbit…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
  - CWE-269
vendor: Red Hat
product: rhoai/odh-dashboard-rhel9
affected:
  - rhoai/odh-dashboard-rhel9 (all versions)
  - rhoai/odh-dashboard-rhel9 (all versions)
  - rhoai/odh-dashboard-rhel9 (all versions)
  - rhoai/odh-mod-arch-automl-rhel9
  - rhoai/odh-mod-arch-autorag-rhel9
  - rhoai/odh-mod-arch-eval-hub-rhel9
  - rhoai/odh-mod-arch-gen-ai-rhel9
  - rhoai/odh-mod-arch-maas-rhel9
  - rhoai/odh-mod-arch-mlflow-rhel9
  - rhoai/odh-mod-arch-model-registry-rhel9
published: '2026-08-10'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T10:16:44.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18950'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:53261'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53262'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:53263'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18950'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2511170'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-11T17:44:28.696778Z'
epss: 0.00523
epssPercentile: 0.42097
ingestedAt: '2026-09-28T10:07:17.785Z'
---

## Overview

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to privilege escalation, where an attacker gains unauthorized elevated access within their namespace and potentially persistent control over the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
