YAML Injection Vulnerability in OpenShift Lifecyle Manager by Red Hat
CVE-2026-18874
6.2MEDIUM
What is CVE-2026-18874?
A vulnerability exists in the volsync-addon-controller, which allows attackers to inject malicious YAML code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This issue is caused by improper escaping of annotation values, which could result in unauthorized changes to OLM Subscription configurations. Systems enabling the 'volsync-addon-deploy-type: olm' annotation are particularly at risk, potentially leading to significant impacts on software management within the cluster.