A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the user to enable and execute untrusted remote code, leading to arbitrary code execution within the cluster.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 21:17
Updated : 2026-08-27 17:17
NVD link : CVE-2026-15467
Mitre link : CVE-2026-15467
CVE.ORG link : CVE-2026-15467
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment
