YAML Injection Vulnerability in OpenShift Lifecyle Manager by Red Hat
CVE-2026-18874

6.2MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
19 August 2026

What is CVE-2026-18874?

A vulnerability exists in the volsync-addon-controller, which allows attackers to inject malicious YAML code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This issue is caused by improper escaping of annotation values, which could result in unauthorized changes to OLM Subscription configurations. Systems enabling the 'volsync-addon-deploy-type: olm' annotation are particularly at risk, potentially leading to significant impacts on software management within the cluster.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.