8.1

CVE-2026-15467

Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat OpenShift AI 2.25
Default Statusaffected
Version 1785187119
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI 3.3
Default Statusaffected
Version 1785187521
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat OpenShift AI 3.4
Default Statusaffected
Version 1784993206
Version < *
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://access.redhat.com/security/cve/CVE-2026-15467
https://bugzilla.redhat.com/show_bug.cgi?id=2499086
https://access.redhat.com/errata/RHSA-2026:53263
https://access.redhat.com/errata/RHSA-2026:53261
https://access.redhat.com/errata/RHSA-2026:53262