Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15581

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

Отчет

This vulnerability is rated as Important. The TrustyAI Service (TAS) in Red Hat OpenShift AI (RHOAI) deployments exposes its backend API without authentication to any pod on the cluster network, bypassing the intended kube-rbac-proxy security control. This allows unauthorized pods in other namespaces to access, tamper with, or delete another tenant's TAS monitoring data and configuration, leading to data integrity and availability concerns.

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2499637trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide

EPSS

Процентиль: 17%
0.00252
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
7 дней назад

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

CVSS3: 8
github
7 дней назад

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

EPSS

Процентиль: 17%
0.00252
Низкий

8 High

CVSS3