CVE-2026-15467
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedA flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster. Source description excerpt; complete tracked detail loads below.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-10 20:44 UTC · Source last updated: 2026-08-10 21:08 UTC · Tracker data as of: 2026-08-10 22:17 UTC
What is affected
ReportedRed Hat — Red Hat OpenShift AI (RHOAI). Product-level identification only; no affected-version conclusion is available from this field.
Evidence: Source reported · Source: CVE record · Source last published: 2026-08-10 20:44 UTC · Source last updated: 2026-08-10 21:08 UTC · Tracker data as of: 2026-08-10 22:17 UTC
Urgency and basis
ReportedTrack* · 215.2
Evidence: Tracker computed · Tracker decision tier from the evidence detailed below · Source last updated: 2026-08-10 21:08 UTC · Tracker data as of: 2026-08-10 22:17 UTC
Exploitation evidence
Not reportedNot reported by tracked sources.
What to do
Not reportedNot reported by tracked sources.
Evidence detail
Loading the full tracker evidence record…