CVE-2026-15378Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from cloud metadata services, Kubernetes API, internal MinIO, and other internal network endpoints. Additionally, it enables local file reads of critical data such as service account tokens and pod secrets.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-16)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-16: 2PoC Mentioned / Linked · 2026-07-16: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-16: 207-1007-1107-16
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-101
Patch1
2026-07-111
Disclosure1
2026-07-162
Disclosure2
Full discourse4 posts
  • ThreatWire@ThreatWire_
    Disclosure

    🚨 CVE-2026-15378: A blind SSRF vulnerability in Red Hat OpenShift AI could expose cloud credentials and Kubernetes secrets through the guardrails-detectors component. #CyberSecurity #CVE #OpenShift #Kubernetes #ThreatWire

    Post summary

    The tweet announces a newly disclosed blind SSRF vulnerability (CVE‑2026‑15378) in Red Hat OpenShift AI’s guardrails‑detectors component that could expose cloud credentials and Kubernetes secrets.

    01022277
    1.3K followersView on X
  • Sami Laiho@samilaiho
    Disclosure

    Critical vulnerability in Red Hat OpenShift AI (RHOAI) URL: https://access.redhat.com/security/cve/cve-2026-15378 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.3

    Post summary

    Red Hat announces a critical CVE (cve‑2026‑15378) for OpenShift AI with a CVSS 9.3 score and an official fix available.

    01020586
    30.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-15378 is a blind SSRF in Red Hat OpenShift AI. The guardrails-detectors flaw exposes cloud credentials and Kubernetes secrets. #OpenShiftAI #CVE202615378 #SSRF #RedHat #Kubernetes http://securityonline.info/openshift-ai-ssrf-cve-2026-15378/

    Post summary

    CVE-2026-15378 is disclosed as a blind SSRF flaw in Red Hat OpenShift AI that can expose cloud credentials and Kubernetes secrets, with a link to further information.

    00020390
    12.9K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-15378 — CVSS 9.3/10 █████████░ A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/Ago8kLgF3P

    Post summary

    A critical vulnerability (CVE‑2026‑15378) with CVSS 9.3/10 in the guardrails‑detectors component has been identified, and a patch has been released.

    1000090
    65 followersView on X

Explore more