A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 21:17
Updated : 2026-08-27 17:17
NVD link : CVE-2026-13717
Mitre link : CVE-2026-13717
CVE.ORG link : CVE-2026-13717
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
