CVE-2026-15581
8
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-306: Missing Authentication for Critical Function
References
- https://access.redhat.com/security/cve/CVE-2026-15581
- https://bugzilla.redhat.com/show_bug.cgi?id=2499637
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.