Arbitrary URL Vulnerability in Red Hat OpenShift's Cost Management Metrics
CVE-2026-18381

7.6HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
30 July 2026

What is CVE-2026-18381?

A vulnerability exists within the koku-metrics-operator used by Red Hat OpenShift, specifically in the CostManagementMetricsConfig custom resource. This flaw allows users with edit permissions to specify an arbitrary upload URL. Consequently, the operator sends queries to this user-defined URL while attaching its own Kubernetes service-account bearer token. As a result, an attacker can steal the service-account token, leading to potential unauthorized access and compromise of sensitive data.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.