CVE-2026-15467

8.1

Red Hat · OpenShift AI

A vulnerability exists in the trustyai-service-operator LMEvalJob controller of Red Hat OpenShift AI 3.3, allowing for incorrect privilege assignment.

Executive summary

A high-severity privilege assignment flaw in the Red Hat OpenShift AI 3.3 LMEvalJob controller could allow authenticated attackers to gain unauthorized elevated access.

Vulnerability

The vulnerability is an incorrect privilege assignment (CWE-266) within the LMEvalJob controller. The CVSS vector (PR:L) indicates that a low-privileged authenticated user can exploit this flaw to impact confidentiality and integrity.

Business impact

Successful exploitation allows an authenticated user to perform unauthorized actions or access sensitive data, potentially leading to a compromise of the AI service infrastructure. With a CVSS score of 8.1, this represents a significant risk to organizational data security and system integrity, necessitating prompt remediation to prevent internal abuse.

Remediation

Immediate Action: Update to Red Hat OpenShift AI 3.3, specifically utilizing the build/release 1785187521 or later, as documented in RHSA-2026:53263.

Proactive Monitoring: Review audit logs for unusual LMEvalJob controller activity or unauthorized privilege escalation patterns within the OpenShift cluster.

Compensating Controls: Implement strict Role-Based Access Control (RBAC) policies within OpenShift to limit the permissions of users capable of interacting with the LMEvalJob controller.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The 8.1 CVSS score underscores the high risk posed by this privilege assignment flaw. Administrators should prioritize the application of the vendor-provided security updates to ensure the integrity of the OpenShift AI environment.

More Red Hat CVEs