CVE-2026-15581

8.0

Red Hat · OpenShift AI

A flaw in the TrustyAI Service (TAS) deployment of Red Hat OpenShift AI 3.3 results in missing authentication for critical functions.

Executive summary

A critical authentication bypass vulnerability in Red Hat OpenShift AI 3.3 could allow adjacent attackers to compromise the TrustyAI Service.

Vulnerability

This vulnerability is caused by missing authentication for critical functions (CWE-306) in the TrustyAI Service. The CVSS vector (AV:A/PR:L) indicates that an authenticated user on the adjacent network can impact the confidentiality, integrity, and availability of the service.

Business impact

The lack of authentication for sensitive functions exposes the TrustyAI Service to full compromise by authorized users on the same network. Given the CVSS score of 8.0, this vulnerability poses a high risk to the availability and data integrity of AI-driven workflows, which could result in significant operational disruption.

Remediation

Immediate Action: Upgrade to Red Hat OpenShift AI 3.3, specifically utilizing the build/release 1785187521 or later, as detailed in the official Red Hat security advisory RHSA-2026:53263.

Proactive Monitoring: Monitor network traffic and authentication logs for anomalous access attempts targeting the TrustyAI Service endpoints.

Compensating Controls: Ensure that network segmentation is enforced to limit access to the TAS deployment to authorized personnel only, reducing the risk of adjacent network exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for total service compromise, it is imperative that organizations apply the provided updates immediately. Verify that all instances of the TrustyAI Service are patched to the required version to eliminate this authentication gap.

More Red Hat CVEs