CVE-2026-15467: Red Hat Openshift Ai 2.25
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Affected products
- Red Hat Red Hat Openshift Ai 2.25: before 1785187119 (fixed in 1785187119)
- Red Hat Red Hat Openshift Ai 3.3: before 1785187521 (fixed in 1785187521)
- Red Hat Red Hat Openshift Ai 3.4: before 1784993206 (fixed in 1784993206); before 1786614608 (fixed in 1786614608)
- Red Hat Red Hat Openshift Ai 3.5: before 1786552271 (fixed in 1786552271); before 1786552250 (fixed in 1786552250)
Published 2026-08-10. Last modified 2026-09-21.