What is CVE-2026-13717?
An improper configuration in the Red Hat OpenShift AI (RHOAI) MaaS Gateway allows a low-privileged standard user to intercept, read, log, and alter all MaaS model traffic in a model-serving context, exposing sensitive information like access keys. It is recommended to review the Gateway configuration and apply the latest security updates.
Azərbaycanca: Red Hat OpenShift AI (RHOAI) MaaS Gateway-in düzgün konfiqurasiya edilməməsi səbəbindən aşağı səlahiyyətli standart istifadəçi MaaS model trafikini ələ keçirə, oxuya, dəyişdirə və access keys kimi həssas məlumatları əldə edə bilər. Bu qüsur model-serving kontekstində baş verir. Gateway konfiqurasiyasını yoxlamaq və ən son təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Red Hat
FAQ1
What can a low-privileged user do by exploiting CVE-2026-13717 in the Red Hat OpenShift AI MaaS Gateway?
CVE-2026-13717 allows a low-privileged standard user to intercept, read, log, and alter all MaaS model traffic in a model-serving context, exposing sensitive information like access keys.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.