What is CVE-2026-18381?
A flaw was found in the koku-metrics-operator for Red Hat OpenShift where the CostManagementMetricsConfig custom resource allows a user with edit access to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-defined URL, potentially leading to token theft. Affected users should immediately update the operator or restrict edit permissions on this custom resource.
Azərbaycanca: Red Hat OpenShift üçün koku-metrics-operator-da aşkar edilmiş bu qüsur, xüsusi resursda (CostManagementMetricsConfig) ixtiyari yükləmə URL-i təyin etməyə imkan verir. Operator, istifadəçi tərəfindən təyin edilmiş bu URL-ə göndərdiyi sorğulara öz xidmət hesabı "bearer token"-ini əlavə edir ki, bu da token oğurluğu ilə nəticələnə bilər. Bu resursu redaktə edə bilən istifadəçilər üçün təsir dərəcəsini azaltmaq məqsədilə operator dərhal yenilənməli və ya giriş icazələri məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Red Hat
FAQ2
Which custom resource in CVE-2026-18381 allows specifying an arbitrary upload URL?
The CostManagementMetricsConfig custom resource allows a user with edit access to specify an arbitrary upload URL.
What does the operator attach to queries sent to the user-defined URL?
The operator attaches its own Kubernetes service-account bearer token to queries sent to the user-defined URL.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.