Junglewise Threat Intelligence

CVE-2026-15063: Red Hat trustyai-service-operator authentication bypass in gorch service

CVE-2026-15063 · Severity: medium · CVSS 6.3 · Published 2026-07-08

Vendors: Red Hat.

Executive brief

A security flaw was discovered in the TrustyAI service operator, a component used for monitoring and explaining AI models within Red Hat OpenShift AI. Even when security authentication is turned on, certain internal communication ports remain unprotected and accessible to other applications within the same network cluster. This could allow an unauthorized user or a compromised application to bypass security controls and access sensitive performance metrics and model data.

Technical details

A missing authentication vulnerability (CWE-306) exists in the gorch service template within the trustyai-service-operator. The service template (gorch/templates/service.tmpl.yaml) continues to expose unproxied ports 8032 (orchestrator) and 8080 (detector metrics) even when authentication is enabled via annotations. Because the kube-rbac-proxy is configured to use the Service DNS as its upstream, these ports remain reachable to any pod on the cluster network. An attacker with low privileges within the cluster can bypass the kube-rbac-proxy entirely by connecting directly to these ports, leading to unauthorized access to sensitive metrics.

Affected products

  • Red Hat Red Hat OpenShift AI (RHOAI) unspecified
  • Red Hat trustyai-service-operator unspecified

Timeline

  • 2026-07-08: disclosed: Vulnerability reported via Red Hat Bugzilla and NVD

References