Sceawere

Vulnerability Detail

CVE-2026-13717UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RHOAI MaaS Gateway Configuration Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Red Hat
Product
Red Hat OpenShift AI (RHOAI)
Attack Type
Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-10T21:17:19.343Z",
  "pubdate": "2026-08-10T21:17:19.343Z",
  "executiveSummary": "A vulnerability has been identified in the Red Hat OpenShift AI (RHOAI) MaaS Gateway involving an improper configuration of the Gateway within a model-serving context. This security flaw introduces significant information disclosure and data tampering risks across affected systems and products.\nThe vulnerability allows an unprivileged attacker possessing standard user credentials and low privileges to compromise model-serving traffic integrity and confidentiality. Specifically, a threat actor can intercept, read, log, and actively alter all Model-as-a-Service (MaaS) model traffic flowing through the improperly configured Gateway component.\nThe compromise of MaaS traffic directly exposes highly sensitive information, including authentication access keys, proprietary input prompts, and generated model outputs. Furthermore, the capability to alter transit traffic enables arbitrary data tampering within the model-serving pipeline.\nExploitation of this vulnerability requires low-privilege standard user access within the environment, bypassing standard isolation mechanisms designed to protect multi-tenant or shared model-serving infrastructures. The resultant risk implications include severe confidentiality breaches, intellectual property theft, session hijacking via leaked access keys, and ingestion or output manipulation affecting AI model reliability.",
  "technicalDetails": "The root cause of the vulnerability stems from an improper configuration of the MaaS Gateway component within the Red Hat OpenShift AI (RHOAI) model-serving architecture. This misconfiguration fails to properly enforce boundary isolation, access control enforcement, and encryption or route segregation for model-serving traffic traversing the gateway.\nThe vulnerable component is the MaaS Gateway in the Red Hat OpenShift AI (RHOAI) ecosystem. Authentication requirements are minimal, as the attack can be executed by a standard user operating with low privileges within the system.\nThe attack flow proceeds as follows: First, a standard user with low privileges identifies the misconfigured MaaS Gateway routing or proxy layer handling model-serving requests and responses. Due to the improper configuration lacking strict tenancy segmentation or authorization checks, the low-privileged user establishes a positioning mechanism to observe or route traffic transiting the gateway.\nSecond, as legitimate clients and applications communicate with the model-serving endpoints, the attacker intercepts the network traffic payload. Because traffic lacks adequate cryptographic isolation or strict access control at the gateway level, the attacker reads sensitive data fields contained within the payloads.\nThird, the intercepted data includes confidential access keys, user input prompts, and model outputs, leading to immediate information disclosure. Additionally, the attacker leverages the lack of traffic integrity controls to alter the contents of the requests or responses in transit, achieving data tampering.\nPost-exploitation impact includes the permanent leakage of operational access keys enabling further unauthorized access, exposure of confidential prompts and intellectual property, and malicious modification of model inputs or outputs which can corrupt downstream analytical processes or system behaviors."
}
CVE-2026-13717: RHOAI MaaS Gateway Configuration Flaw (HIGH Severity, CVSS: 8.8) - Sceawere