Vulnerability in Koku Metrics Operator Exposes Sensitive OAuth Credentials
CVE-2026-18382
6.8MEDIUM
What is CVE-2026-18382?
A security flaw in Koku Metrics Operator permits users with editing privileges on the CostManagementMetricsConfig custom resource to specify an external OAuth token endpoint. When the authentication type is set to service-account, the operator inadvertently sends sensitive Red Hat SSO client_id and client_secret information to this user-controllable URL, potentially allowing unauthorized users to capture these credentials and exploit them for malicious activities.