Description
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
Published: 2026-08-10
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Red Hat OpenShift AI MaaS Gateway is misconfigured, allowing a standard user with low privileges to intercept, log, and alter all model‑serving traffic by hijacking the default AllowedRoutes.namespaces.from setting. This flaw exposes sensitive keys, prompts, and outputs, leading to information disclosure and potential data tampering. The weakness is a classic improper access control, identified as CWE‑284.

Affected Systems

Vendors impacted include Red Hat, specifically the OpenShift AI (RHOAI) platform that hosts the MaaS Gateway. No specific version ranges are listed, so any RHOAI installation that includes the MaaS Gateway component may be affected until a corrective update is applied.

Risk and Exploitability

The CVSS base score of 8.8 classifies the issue as high severity, and while an EPSS score is not currently available, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector operates inside the cluster; a malicious actor in an authorized namespace can exploit the misconfiguration without additional network access or elevated privileges. Given the sensitivity of the exposed data, the risk of compromise is significant and should be addressed promptly.

Generated by OpenCVE AI on August 10, 2026 at 22:46 UTC.

Remediation

Vendor Workaround

You can restrict Gateway access to some namespaces only. However, it does not prevent someone from an authorized namespace to hijack the traffic of another. Fully locking down access to the MaaS Gateway is a solution, however it defeats the self-service approach of the component.


OpenCVE Recommended Actions

  • Apply the latest RHOAI patch that corrects the Gateway configuration
  • Configure the MaaS Gateway to limit AllowedRoutes to specific namespaces only
  • If the self‑service model cannot be tolerated, disable MaaS Gateway access entirely

Generated by OpenCVE AI on August 10, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Openshift Ai (rhoai)
Vendors & Products Red Hat
Red Hat red Hat Openshift Ai (rhoai)

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 10 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
Title Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: all allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)
First Time appeared Redhat
Redhat openshift Ai
Weaknesses CWE-284
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Red Hat Red Hat Openshift Ai (rhoai)
Redhat Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-10T20:44:01.309Z

Reserved: 2026-06-29T14:05:37.264Z

Link: CVE-2026-13717

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-10T18:31:42Z

Links: CVE-2026-13717 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T02:00:06Z

Weaknesses