SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-18378

HIGH · CVSS 7.6 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability exists in the koku-metrics-operator, where the CostManagementMetricsConfig custom resource allows users to specify an arbitrary upload URL. This flaw can lead to the exposure of the cluster-global Red Hat Cloud pull-secret bearer token in HTTP requests, enabling attackers to gain unauthorized access to sensitive resources. Organizations using this operator, especially those with default token authentication, should prioritize remediation to mitigate the risk of credential theft.

CVE
CVE-2026-18378
Severity
HIGH
CVSS
7.6
EPSS
0.23%

Original NVD Description

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.

Related CVEs

Other vulnerabilities affecting the same vendor(s)