Skip to content
Red HatCVE-2026-15063

Red Hat gorch service template: missing authentication

Medium6.3CVE-2026-15063 · Published Jul 8, 2026 · updated Aug 31, 2026

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift AI (RHOAI)
Product
all versionsNo fix yet
trustyai-service-operator
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-306

More Red Hat advisories

All Red Hat
Advisory
Red Hat, Inc.: CVE records (CNA): denial of service
Medium6.5Jul 8
Red Hat TrustyAI Service Operator.: information disclosure
Medium6.3Jul 8
A flaw was found in 389 Directory Server
Low3.7Jul 8
Red Hat Jastow: cross-site scripting
Medium6.5Jul 7
Red Hat GStreamer: incorrect control flow
Low3.7Jul 7
Red Hat 389-ds-base: attacker could detect plaintext equality across encrypted
Medium4.4Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.