Red HatCVE-2026-15467
Red Hat trustyai-service-operator: remote code execution
High8.1CVE-2026-15467 · Published Aug 10, 2026 · updated Sep 21, 2026
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-266
- www.cve.org/CVERecord?id=CVE-2026-15467
- nvd.nist.gov/vuln/detail/CVE-2026-15467
- access.redhat.com/errata/RHSA-2026:53261
- access.redhat.com/errata/RHSA-2026:53262
- access.redhat.com/errata/RHSA-2026:53263
- access.redhat.com/errata/RHSA-2026:60367
- access.redhat.com/errata/RHSA-2026:60520
- access.redhat.com/security/cve/CVE-2026-15467
- bugzilla.redhat.com/show_bug.cgi?id=2499086
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |