CVE-2026-15581
8
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift AI 2.25 | 1785187119 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 2.25 | 1787330073 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 3.3 | 1785187521 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 3.4 | 1784993206 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 3.4 | 1786614608 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552271 < * | unaffected |
| Red Hat | Red Hat OpenShift AI 3.5 | 1786552250 < * | unaffected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2026:53261
- https://access.redhat.com/errata/RHSA-2026:53262
- https://access.redhat.com/errata/RHSA-2026:53263
- https://access.redhat.com/errata/RHSA-2026:60367
- https://access.redhat.com/errata/RHSA-2026:60520
- https://access.redhat.com/errata/RHSA-2026:65126
- https://access.redhat.com/security/cve/CVE-2026-15581
- https://bugzilla.redhat.com/show_bug.cgi?id=2499637
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.