Arbitrary URL Vulnerability in Red Hat OpenShift's Cost Management Metrics
CVE-2026-18381
7.6HIGH
What is CVE-2026-18381?
A vulnerability exists within the koku-metrics-operator used by Red Hat OpenShift, specifically in the CostManagementMetricsConfig custom resource. This flaw allows users with edit permissions to specify an arbitrary upload URL. Consequently, the operator sends queries to this user-defined URL while attaching its own Kubernetes service-account bearer token. As a result, an attacker can steal the service-account token, leading to potential unauthorized access and compromise of sensitive data.