What is CVE-2026-18382?
CVE-2026-18382 is a vulnerability in koku-metrics-operator where a user with edit permissions on CostManagementMetricsConfig custom resource can specify an arbitrary OAuth token endpoint. When authentication.type is set to 'service-account', this flaw could lead to the exposure of the tenant's Red Hat SSO client_id and client_secret. Updating to the latest version is recommended.
Azərbaycanca: CVE-2026-18382 koku-metrics-operator-da aşkar edilmiş boşluqdur. Bu boşluq CostManagementMetricsConfig custom resource-unu redaktə edə bilən istifadəçiyə ixtiyari OAuth token endpoint-i təyin etməyə imkan verir ki, bu da tenant-in Red Hat SSO məlumatlarının (client_id, client_secret) yanlış ünvana göndərilməsinə səbəb ola bilər. Bu zəiflikdən qorunmaq üçün operatoru ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What resource must an attacker be able to edit to exploit CVE-2026-18382?
The attacker must be able to edit the CostManagementMetricsConfig custom resource.
Under which authentication type setting can CVE-2026-18382 be exploited?
This vulnerability can be exploited when `authentication.type` is set to 'service-account'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.