Authentication Bypass Vulnerability in TrustyAI Service by Red Hat
CVE-2026-15581

8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-15581?

A vulnerability has been identified in the TrustyAI Service deployment that enables any pod within the cluster network to bypass authentication mechanisms. This flaw allows unauthorized access to the TAS backend API, potentially enabling an attacker to read, modify, or delete critical monitoring data and configurations. Furthermore, attackers could inject arbitrary data into the service, which may disrupt operations for tenants relying on the TrustyAI Service.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.