What is CVE-2026-18378?
CVE-2026-18378 is a flaw in the koku-metrics-operator where users who can edit the CostManagementMetricsConfig custom resource can specify an arbitrary upload URL. When authentication.type is set to token (the default), this attaches the cluster-global Red Hat Cloud pull-secret bearer token to the request.
Azərbaycanca: CVE-2026-18378 koku-metrics-operator-da aşkar edilmiş boşluqdur. İstifadəçi CostManagementMetricsConfig özəl resursunu redaktə edərək özbaşına yükləmə URL-i təyin edə bilir, bu isə `token` autentifikasiya növü aktiv olduqda cluster səviyyəli Red Hat Cloud pull-secret bearer token-inin ifşasına səbəb olur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Red Hat
FAQ1
Which authentication type in koku-metrics-operator triggers the CVE-2026-18378 flaw?
The flaw occurs when the `authentication.type` is set to `token`, which is the default configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.