YAML Injection Vulnerability in OpenShift Lifecyle Manager by Red Hat
CVE-2026-18874
6.2MEDIUM
Key Information:
What is CVE-2026-18874?
A vulnerability exists in the volsync-addon-controller, which allows attackers to inject malicious YAML code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This issue is caused by improper escaping of annotation values, which could result in unauthorized changes to OLM Subscription configurations. Systems enabling the 'volsync-addon-deploy-type: olm' annotation are particularly at risk, potentially leading to significant impacts on software management within the cluster.
Affected Version(s)
Red Hat Advanced Cluster Management for Kubernetes 2.11 1787683560
Red Hat Advanced Cluster Management for Kubernetes 2.13 1787266564
Red Hat Advanced Cluster Management for Kubernetes 2.14 1787266564