Description
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
Published: 2026-07-30
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the koku‑metrics‑operator allows a user who can edit the CostManagementMetricsConfig custom resource to specify an arbitrary upload URL. The operator then attaches its own Kubernetes service‑account bearer token to requests sent to that URL, giving the attacker the ability to obtain the token. This is a CWE‑918 data‑exfiltration weakness that can compromise the confidentiality and integrity of cluster resources by providing a credential that can be used to impersonate privileged service accounts.

Affected Systems

The vulnerability affects Red Hat Cost Management Metrics Operator deployed on OpenShift. The official vendor name is "Red Hat Cost Management Metrics Operator". No specific version range is provided in the public data, so the applicability extends to all released versions of this operator.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity. The EPSS score of <1% (0.00197) indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers need permission to modify the CostManagementMetricsConfig resource, which typically requires cluster‑level or administrator privileges. The flaw therefore relies on privileged or elevated access, but once that is obtained the attacker can effortlessly exfiltrate a service‑account token by pointing the operator to a malicious URL.

Generated by OpenCVE AI on August 2, 2026 at 05:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Red Hat update that patches the koku‑metrics‑operator to reject arbitrary upload URLs or stop attaching the bearer token to outbound requests.
  • If a is not yet available, tighten RBAC so that only trusted users can edit the CostManagementMetricsConfig resource; revoke edit permissions from all other roles.
  • Audit existing CostManagementMetricsConfig instances and remove any non‑trusted upload URLs, ensuring that only whitelisted endpoints are used.
  • As an interim workaround, disable the operator’s automatic bearer‑token attachment until the formal patch is deployed.

Generated by OpenCVE AI on August 2, 2026 at 05:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cost Management Metrics Operator
CPEs cpe:2.3:a:redhat:cost_management_metrics_operator:-:*:*:*:*:openshift:*:*
Vendors & Products Redhat cost Management Metrics Operator

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat cost Management Metrics Operator
Vendors & Products Red Hat
Red Hat cost Management Metrics Operator

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
Title Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address
First Time appeared Redhat
Redhat cost Management
Weaknesses CWE-918
CPEs cpe:/a:redhat:cost_management:4
Vendors & Products Redhat
Redhat cost Management
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Red Hat Cost Management Metrics Operator
Redhat Cost Management Cost Management Metrics Operator
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-30T12:14:46.389Z

Reserved: 2026-07-30T11:37:06.496Z

Link: CVE-2026-18381

cve-icon Vulnrichment

Updated: 2026-07-30T12:14:34.231Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T12:17:27.693

Modified: 2026-08-12T19:27:29.393

Link: CVE-2026-18381

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:00:00Z

Links: CVE-2026-18381 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)