CVE-2026-13717: Red Hat Openshift Ai 3.4

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

Affected products

  • Red Hat Red Hat Openshift Ai 3.4: before 1786123541 (fixed in 1786123541); before 1787153684 (fixed in 1787153684)
  • Red Hat Red Hat Openshift Ai Rhoai

Published 2026-08-10. Last modified 2026-08-27.