CVE-2026-13717

high

Description

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

References

https://bugzilla.redhat.com/show_bug.cgi?id=2494203

https://access.redhat.com/security/cve/CVE-2026-13717

https://access.redhat.com/errata/RHSA-2026:53262

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-14

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00308