A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. (CVE-2026-13717)
A security flaw in the Red Hat OpenShift AI (RHOAI) MaaS Gateway allows a low-privileged standard user to intercept, read, log, and modify all model-serving traffic. This includes sensitive data such as access keys, input prompts, and outputs. The issue arises from an insecure default configuration that permits unauthorized access within namespaces authorized to use the MaaS Gateway. This leads to significant information disclosure and data tampering risks.
AI Analysis
Technical Summary
CVE-2026-13717 is a vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway caused by improper access control due to insecure default configuration. In a model-serving context, this flaw allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic, including sensitive information like access keys, input prompts, and outputs. The vulnerability affects any namespace authorized to use the MaaS Gateway, enabling namespace users to hijack shared model-serving traffic. The root cause is an overly permissive default setting for allowedRoutes.namespaces.from, which allows all namespaces access. This vulnerability is tracked as CWE-284 (Improper Access Control) and has a CVSS v3.1 base score of 8.8 (high severity) with network attack vector, low complexity, low privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
The vulnerability enables a low-privileged user within an authorized namespace to intercept and manipulate all traffic passing through the MaaS Gateway, including sensitive data such as access keys, input prompts, and model outputs. This results in significant information disclosure and data tampering, potentially compromising the confidentiality, integrity, and availability of the model-serving infrastructure and its data.
Mitigation Recommendations
A fix is available in Red Hat OpenShift AI version 3.4.3. Users should upgrade to this version following Red Hat's official documentation to fully apply the errata update. As a mitigation, Gateway access can be restricted to specific namespaces, but this does not prevent users within authorized namespaces from hijacking traffic of others. Fully locking down access to the MaaS Gateway is possible but may defeat the component's self-service design. Therefore, upgrading to the fixed version is the recommended remediation.
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. (CVE-2026-13717)
Description
A security flaw in the Red Hat OpenShift AI (RHOAI) MaaS Gateway allows a low-privileged standard user to intercept, read, log, and modify all model-serving traffic. This includes sensitive data such as access keys, input prompts, and outputs. The issue arises from an insecure default configuration that permits unauthorized access within namespaces authorized to use the MaaS Gateway. This leads to significant information disclosure and data tampering risks.
CVSS v3.1
Score 8.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13717 is a vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway caused by improper access control due to insecure default configuration. In a model-serving context, this flaw allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic, including sensitive information like access keys, input prompts, and outputs. The vulnerability affects any namespace authorized to use the MaaS Gateway, enabling namespace users to hijack shared model-serving traffic. The root cause is an overly permissive default setting for allowedRoutes.namespaces.from, which allows all namespaces access. This vulnerability is tracked as CWE-284 (Improper Access Control) and has a CVSS v3.1 base score of 8.8 (high severity) with network attack vector, low complexity, low privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
The vulnerability enables a low-privileged user within an authorized namespace to intercept and manipulate all traffic passing through the MaaS Gateway, including sensitive data such as access keys, input prompts, and model outputs. This results in significant information disclosure and data tampering, potentially compromising the confidentiality, integrity, and availability of the model-serving infrastructure and its data.
Mitigation Recommendations
A fix is available in Red Hat OpenShift AI version 3.4.3. Users should upgrade to this version following Red Hat's official documentation to fully apply the errata update. As a mitigation, Gateway access can be restricted to specific namespaces, but this does not prevent users within authorized namespaces from hijacking traffic of others. Fully locking down access to the MaaS Gateway is possible but may defeat the component's self-service design. Therefore, upgrading to the fixed version is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-335x-vvmj-55qx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-13717"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Patch Information
Threat ID: 6a7c9b73bf8831d539ce0dbf
Added to database: 08/12/2026, 16:12:35 UTC
Last enriched: 08/12/2026, 17:34:47 UTC
Last updated: 08/12/2026, 17:34:47 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.