SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15063

MEDIUM · CVSS 6.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The gorch service template within the trustyai-service-operator has a vulnerability that exposes unproxied orchestrator and detector metrics ports, even with authentication enabled. This flaw allows any pod on the cluster network to access these metrics directly, circumventing kube-rbac-proxy's authentication, potentially leading to unauthorized access to sensitive metrics. Organizations using the trustyai-service-operator should prioritize addressing this vulnerability to safeguard their cluster's security.

CVE
CVE-2026-15063
Severity
MEDIUM
CVSS
6.3
EPSS
0.18%

Original NVD Description

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the kube-rbac-proxy and its authentication mechanisms. This could lead to unauthorized access to the orchestrator and detector metrics.