Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat cost Management Metrics Operator
|
|
| CPEs | cpe:2.3:a:redhat:cost_management_metrics_operator:-:*:*:*:*:openshift:*:* | |
| Vendors & Products |
Redhat cost Management Metrics Operator
|
Fri, 31 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat cost Management Metrics Operator |
|
| Vendors & Products |
Red Hat
Red Hat cost Management Metrics Operator |
Thu, 30 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token. | |
| Title | Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address | |
| First Time appeared |
Redhat
Redhat cost Management |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:cost_management:4 | |
| Vendors & Products |
Redhat
Redhat cost Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-30T12:14:46.389Z
Reserved: 2026-07-30T11:37:06.496Z
Link: CVE-2026-18381
Updated: 2026-07-30T12:14:34.231Z
Status : Analyzed
Published: 2026-07-30T12:17:27.693
Modified: 2026-08-12T19:27:29.393
Link: CVE-2026-18381
OpenCVE Enrichment
Updated: 2026-08-02T05:30:06Z