← All Advisories

CVE-2026-15581

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-15581

Key Details

CVECVE-2026-15581
CVSS Score / Version8.0 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Red Hat OpenShift AI 3.3, Red Hat Red Hat OpenShift AI 3.4, Red Hat Red Hat OpenShift AI 2.25, and Red Hat Red Hat OpenShift AI 3.5
Classified asCWE-306 (Missing Authentication for Critical Function)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat OpenShift AI 2.25
Red HatRed Hat OpenShift AI 3.5
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15581
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15581