Red HatCVE-2026-15063
Red Hat gorch service template: missing authentication
Medium6.3CVE-2026-15063 · Published Jul 8, 2026 · updated Aug 31, 2026
A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift AI (RHOAI) Product | all versions | No fix yet |
| trustyai-service-operator Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Red Hat, Inc.: CVE records (CNA): denial of service | Medium6.5 | Red Hat+1 more |
| Jul 8 | Red Hat TrustyAI Service Operator.: information disclosure | Medium6.3 | No fix yet |
| Jul 8 | A flaw was found in 389 Directory Server | Low3.7 | No fix yet |
| Jul 7 | Red Hat Jastow: cross-site scripting | Medium6.5 | No fix yet |
| Jul 7 | Red Hat GStreamer: incorrect control flow | Low3.7 | No fix yet |
| Jul 7 | Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted | Medium4.4 | No fix yet |