CVE-2026-15581: Red Hat Openshift Ai 2.25

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

Affected products

  • Red Hat Red Hat Openshift Ai 2.25: before 1785187119 (fixed in 1785187119); before 1787330073 (fixed in 1787330073)
  • Red Hat Red Hat Openshift Ai 3.3: before 1785187521 (fixed in 1785187521)
  • Red Hat Red Hat Openshift Ai 3.4: before 1784993206 (fixed in 1784993206); before 1786614608 (fixed in 1786614608)
  • Red Hat Red Hat Openshift Ai 3.5: before 1786552271 (fixed in 1786552271); before 1786552250 (fixed in 1786552250)

Published 2026-08-10. Last modified 2026-09-21.