{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/openshift-ai/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-13717"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenShift AI"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-security","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA security flaw identified as CVE-2026-13717 affects the Red Hat OpenShift AI (RHOAI) MaaS Gateway. The vulnerability stems from improper Gateway configuration within a model-serving deployment. This misconfiguration permits a standard, low-privileged user to intercept, log, read, and modify traffic routed through the MaaS Gateway. Because this traffic often includes sensitive information such as API access keys, input prompts, and model output data, an attacker can exfiltrate credentials or tamper with model inferences. The scope of this threat is limited to environments where RHOAI is deployed with the affected Gateway configuration, creating a significant risk of data breaches within internal AI serving pipelines. Organizations should prioritize updating RHOAI and auditing their Gateway configuration settings to ensure proper isolation of user requests and model responses.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to gain visibility into internal AI workflows and exfiltrate sensitive data. This includes administrative credentials used for model authentication and potentially proprietary input/output data processed by the models. The potential impact spans the compromise of sensitive AI-driven business intelligence and the unauthorized use of model-serving resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patch for RHOAI provided by Red Hat to resolve CVE-2026-13717.\u003c/li\u003e\n\u003cli\u003eAudit RHOAI MaaS Gateway configurations to verify that access controls are strictly applied and that standard users cannot intercept cross-tenant or administrative traffic flows.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous activity in logs generated by the MaaS Gateway, specifically looking for users attempting to access model traffic streams they are not authorized to interact with.\u003c/li\u003e\n\u003cli\u003eReview all stored credentials used within the AI model-serving environment to ensure they remain secure in the event of partial traffic interception.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T23:37:03Z","date_published":"2026-08-10T23:36:33Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rhoai-maas-gateway-vuln/","summary":"A configuration vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway enables low-privileged users to intercept and manipulate model-serving traffic, resulting in the unauthorized disclosure of access keys and AI prompts.","title":"Improper Configuration in Red Hat OpenShift AI MaaS Gateway","url":"https://feed.craftedsignal.io/briefs/2026-08-rhoai-maas-gateway-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenShift AI","version":"https://jsonfeed.org/version/1.1"}