VDB

CVE-2026-15581

CVE-2026-15581 PUBLISHED CVSS 8 HIGH

Reported by redhat · Published August 10, 2026

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift AI 2.251785187119
Red HatRed Hat OpenShift AI 2.251787330073
Red HatRed Hat OpenShift AI 3.31785187521
Red HatRed Hat OpenShift AI 3.41784993206
Red HatRed Hat OpenShift AI 3.41786614608
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 3.51786552250
Red HatRed Hat OpenShift AI 3.51786552271
Red HatRed Hat OpenShift AI 3.51786552250
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI 3.31785187521, 1785187521, 1785187521
Red HatRed Hat OpenShift AI 3.41784993206, 1784993206, 1786614608
Red HatRed Hat OpenShift AI 2.251785187119, 1787330073, 1785187119

Timeline

  • Aug 10, 2026 CVE Published
  • Aug 11, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 5, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 22, 2026 Distribution Patch
  • Sep 22, 2026 Distribution Patch
  • Sep 22, 2026 Distribution Patch

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›