A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 21:17
Updated : 2026-09-08 22:17
NVD link : CVE-2026-15581
Mitre link : CVE-2026-15581
CVE.ORG link : CVE-2026-15581
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
