What is CVE-2026-15467?
A vulnerability in trustyai-service-operator's LMEvalJob controller allows an authenticated user to bypass security policies by configuring a sidecar container. This flaw can lead to untrusted remote code execution within the cluster. It is recommended to restrict authenticated user permissions and apply security patches promptly.
Azərbaycanca: trustyai-service-operator-un LMEvalJob nəzarətçisində autentifikasiya olunmuş istifadəçiyə sidecar konteyneri konfiqurasiya edərək təhlükəsizlik siyasətlərini keçməyə imkan verən zəiflik aşkarlanıb. Bu, etibarsız uzaqdan kod icrasına (remote code execution) və potensial hücumlara səbəb ola bilər. Klaster daxilində autentifikasiya olunmuş istifadəçi icazələrini məhdudlaşdırmaq tövsiyə olunur.
FAQ2
In which component of trustyai-service-operator does CVE-2026-15467 exist?
The vulnerability exists in the LMEvalJob controller of trustyai-service-operator.
What can an authenticated user achieve by exploiting CVE-2026-15467?
An authenticated user can achieve untrusted remote code execution within the cluster by configuring a sidecar container.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.