TrustyAI TAS Auth Bypass: Pods Bypass API Auth
CVE-2026-15581 Published on August 10, 2026
Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-rbac-proxy, exposing unauthenticated quarkus api cluster-wide
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 54 days later.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-15581
Want to know whenever a new CVE is published for Red Hat Openshift Ai? stack.watch will email you.
Affected Versions
Red Hat OpenShift AI 2.25:- Version 1785187119 and below * is unaffected.
- Version 1785187521 and below * is unaffected.
- Version 1784993206 and below * is unaffected.
- Version 1786614608 and below * is unaffected.