GPU VulnDB

Database/AI/ML frameworks & serving

TrustyAI Service Operator: unauthenticated access to AI guardrail and orchestrator APIs

CVE-2026-15044AI/ML frameworks & servingcurated

Impact

Guardrail and orchestrator APIs are reachable without authentication from anywhere on the cluster network. An attacker who can reach them reads or reconfigures the guardrails meant to constrain model behaviour, so the safety layer a deployment depends on can be turned off without touching the model itself.

Who can reach it

Any workload with cluster network access to the operator's services.

What to do

Upgrade the TrustyAI Service Operator to the fixed release from Red Hat, then put a NetworkPolicy in front of the guardrail and orchestrator services and require mTLS between them. The operator restart is a rolling one; no node work.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.