Status: UPDATED
| Advisory ID: CVE-2026-15581
Key Details
| CVE | CVE-2026-15581 |
| CVSS Score / Version | 8.0 (High) / CVSS v3.1 |
| Updated | 2026-09-21 |
| CVSS Vector | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is adjacent; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat OpenShift AI 3.3, Red Hat Red Hat OpenShift AI 3.4, Red Hat Red Hat OpenShift AI 2.25, and Red Hat Red Hat OpenShift AI 3.5 |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References