Sceawere

Vulnerability Detail

CVE-2026-15467UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

trustyai-service-operator LMEvalJob Code Execution Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
5h ago
Vendor
Red Hat
Product
Red Hat OpenShift AI (RHOAI)
Attack Type
Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-10T21:17:19.617Z",
  "pubdate": "2026-08-10T21:17:19.617Z",
  "executiveSummary": "A security vulnerability has been identified within the trustyai-service-operator's LMEvalJob controller, specifically impacting cluster-level security controls. This flaw constitutes an arbitrary code execution vulnerability that allows authenticated users within the Kubernetes cluster to compromise the integrity and security posture of the affected deployment. The risk implications are severe, as successful exploitation bypasses established security policies and permits the execution of untrusted remote code. Attackers require authenticated access within the target cluster and the capability to configure sidecar containers specifically tailored to circumvent container isolation and policy enforcement mechanisms. The vulnerability directly affects the trustyai-service-operator product by exposing its controller logic to improper configuration handling, which malicious actors can leverage to escalate privileges or perform unauthorized actions within the cluster infrastructure. Immediate remediation is required to restrict sidecar container configuration capabilities and enforce strict validation within the LMEvalJob controller.",
  "technicalDetails": "The vulnerability resides in the trustyai-service-operator LMEvalJob controller component. The root cause stems from insufficient input validation and policy enforcement regarding container configurations within the controller's orchestration logic. Specifically, the LMEvalJob controller fails to adequately validate or restrict user-supplied container specifications when orchestrating evaluation jobs, allowing authenticated cluster users to inject and configure unauthorized sidecar containers.\nThe attack flow proceeds as follows: First, an authenticated attacker with access to the Kubernetes cluster crafts a malicious LMEvalJob resource specification. This specification includes a specially configured sidecar container designed to bypass existing admission controllers, security context constraints, or pod security policies enforced by the cluster. Upon submission, the trustyai-service-operator processes the LMEvalJob and deploys the associated pods along with the unauthorized sidecar container.\nBecause the sidecar successfully bypasses the security policy controls, the attacker achieves the ability to execute arbitrary commands, load unverified binaries, or fetch and execute untrusted remote code from external sources. The privilege level of the resulting execution depends on the permissions assigned to the service account associated with the LMEvalJob pod. Post-exploitation impact includes potential lateral movement within the cluster, access to sensitive secrets or data processed by the TrustyAI service, and full compromise of the affected container execution environment."
}
CVE-2026-15467: trustyai-service-operator LMEvalJob Code Execution Vulnerability (HIGH Severity, CVSS: 8.1) - Sceawere