What is CVE-2026-15581?
A vulnerability was found in TrustyAI Service (TAS) deployment that allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. This can lead to unauthorized reading, tampering, or deletion of monitoring data and configurations, as well as arbitrary injection. Immediate network-level access controls and TAS configuration updates are required.
Azərbaycanca: TrustyAI Service (TAS) deployment-da autentifikasiya bypass zəifliyi aşkar edilib. Bu boşluq klaster şəbəkəsindəki istənilən pod-a TAS backend API-ə birbaşa icazəsiz giriş imkanı verir. Təcili olaraq şəbəkə səviyyəsində giriş nəzarəti tətbiq edilməli və TAS yerləşdirmə konfiqurasiyası yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What does the CVE-2026-15581 vulnerability allow in TrustyAI Service (TAS) deployment?
This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API without authorization.
What measures should be taken to mitigate the CVE-2026-15581 vulnerability?
Immediate network-level access controls must be applied and the TAS deployment configuration must be updated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.