Description
A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.
Published: 2026-07-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TrustyAI Service Operator contains a flaw that enables unauthenticated access to the AI guardrails and orchestrator APIs when a specific security setting is disabled during deployment of services such as gorch or NemoGuardrails. Because a program running within the same OpenShift cluster can call these APIs, an attacker can read sensitive configuration and model data and possibly perform limited changes. This vulnerability corresponds to the weakness CWE‑200 for Information Exposure.

Affected Systems

Red Hat OpenShift AI (RHOAI) deployments that include the TrustyAI Service Operator are affected whenever the required security setting that protects the communication channels is not enabled. Services like gorch and NemoGuardrails are vulnerable under these conditions; no specific operator version is listed as affected, so all unpatched releases may be susceptible.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in CISA KEV. The likely attack scenario involves an adversary who has already compromised a component inside the cluster; by leveraging the missing authentication they can reach the exposed APIs without privilege escalation. Based on the description, no special privileges beyond normal cluster component access are required for exploitation.

Generated by OpenCVE AI on July 28, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enable the required security setting in the TrustyAI Service Operator configuration to enforce authentication for guardrails and orchestrator APIs.
  • Upgrade to the latest release of the TrustyAI Service Operator once Red Hat issues a patch that resolves the vulnerability.
  • Implement Kubernetes Network Policies or other segmentation controls to restrict communication between intra‑cluster services and the guardrails and orchestrator.

Generated by OpenCVE AI on July 28, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Mon, 13 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 12 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 10 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 10 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the AI guardrails and orchestrator without proper authorization. An attacker could exploit this to gain unauthorized access to sensitive information and potentially make limited changes to the AI models.
Title Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis
First Time appeared Redhat
Redhat openshift Ai
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Redhat Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-14T13:36:08.063Z

Reserved: 2026-07-08T12:13:56.870Z

Link: CVE-2026-15044

cve-icon Vulnrichment

Updated: 2026-07-09T13:41:10.667Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T00:00:00Z

Links: CVE-2026-15044 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor