Boletines de Vulnerabilidades |
CVE-2026-18381 |
|
| Software afectado | KUBERNETES |
| A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-18381 | |






