← All Advisories

Red Hat OpenShift AI MaaS Gateway misconfiguration lets low-privilege user intercept and alter all model traffic and access keys

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-13717

Key Details

CVECVE-2026-13717
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-08-27
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-284 (Improper Access Control)

What to Know

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-13717
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-13717