Improper Configuration in Red Hat OpenShift AI MaaS Gateway
A configuration vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway enables low-privileged users to intercept and manipulate model-serving traffic, resulting in the unauthorized disclosure of access keys and AI prompts.
What's new
- 1. added coverage for OpenShift AI Aug 10, 23:37 via nvd
A security flaw identified as CVE-2026-13717 affects the Red Hat OpenShift AI (RHOAI) MaaS Gateway. The vulnerability stems from improper Gateway configuration within a model-serving deployment. This misconfiguration permits a standard, low-privileged user to intercept, log, read, and modify traffic routed through the MaaS Gateway. Because this traffic often includes sensitive information such as API access keys, input prompts, and model output data, an attacker can exfiltrate credentials or tamper with model inferences. The scope of this threat is limited to environments where RHOAI is deployed with the affected Gateway configuration, creating a significant risk of data breaches within internal AI serving pipelines. Organizations should prioritize updating RHOAI and auditing their Gateway configuration settings to ensure proper isolation of user requests and model responses.
Impact
Successful exploitation of this vulnerability allows unauthorized users to gain visibility into internal AI workflows and exfiltrate sensitive data. This includes administrative credentials used for model authentication and potentially proprietary input/output data processed by the models. The potential impact spans the compromise of sensitive AI-driven business intelligence and the unauthorized use of model-serving resources.
Recommendation
- Apply the security patch for RHOAI provided by Red Hat to resolve CVE-2026-13717.
- Audit RHOAI MaaS Gateway configurations to verify that access controls are strictly applied and that standard users cannot intercept cross-tenant or administrative traffic flows.
- Monitor for anomalous activity in logs generated by the MaaS Gateway, specifically looking for users attempting to access model traffic streams they are not authorized to interact with.
- Review all stored credentials used within the AI model-serving environment to ensure they remain secure in the event of partial traffic interception.
Immediate actions
Patch RHOAI instance to resolve CVE-2026-13717.
Mitigations
Audit MaaS Gateway access controls.
CVE-2026-13717