A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster. | |
| Title | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass protected environment variable filtering, allowing trust_remote_code policy override | |
| First Time appeared |
Redhat
Redhat openshift Ai |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:openshift_ai | |
| Vendors & Products |
Redhat
Redhat openshift Ai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-10T20:44:12.686Z
Reserved: 2026-07-10T21:18:20.245Z
Link: CVE-2026-15467
No data.
No data.
No data.
OpenCVE Enrichment
No data.