Description
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Published: 2026-08-10
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Trustyai Service Operator’s LMEvalJob controller allows an authenticated cluster user to configure a sidecar container that bypasses existing security policies. By doing so, the attacker can enable and execute untrusted remote code, leading to arbitrary code execution inside the cluster. This vulnerability is a privilege escalation flaw (CWE‑266).

Affected Systems

The affected vendor is Red Hat, specifically the Red Hat OpenShift AI platform. The vulnerability impacts the trustyai‑service‑operator component. No specific affected version range is provided in the CVE data, so the patch status of the installed operator is unknown.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, so the current probability of exploitation is unclear, and the vulnerability is not listed in the CISA KEV catalog. Attacks require an authenticated user inside the cluster, suggesting the attack vector is local; however, once in place, the attacker can run arbitrary code throughout the cluster environment.

Generated by OpenCVE AI on August 10, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or update for the trustyai-service-operator to the version that addresses the sidecar bypass flaw.
  • If a patch is not immediately available, restrict or audit sidecar container configurations to enforce the trust_remote_code policy and prevent unauthorized code execution.
  • Review cluster authentication and role bindings to ensure only trusted users have permissions to create or modify LMEvalJob resources, thereby limiting the attack surface.

Generated by OpenCVE AI on August 10, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Openshift Ai (rhoai)
Vendors & Products Red Hat
Red Hat red Hat Openshift Ai (rhoai)

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 10 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Title Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override
First Time appeared Redhat
Redhat openshift Ai
Weaknesses CWE-266
CPEs cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Red Hat Red Hat Openshift Ai (rhoai)
Redhat Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-10T20:44:12.686Z

Reserved: 2026-07-10T21:18:20.245Z

Link: CVE-2026-15467

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-10T18:43:08Z

Links: CVE-2026-15467 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T03:15:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment