Vulnerability in Koku Metrics Operator Exposes Sensitive OAuth Credentials
CVE-2026-18382

6.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
30 July 2026

What is CVE-2026-18382?

A security flaw in Koku Metrics Operator permits users with editing privileges on the CostManagementMetricsConfig custom resource to specify an external OAuth token endpoint. When the authentication type is set to service-account, the operator inadvertently sends sensitive Red Hat SSO client_id and client_secret information to this user-controllable URL, potentially allowing unauthorized users to capture these credentials and exploit them for malicious activities.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.