Description
IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.
No analysis available yet.
Remediation
Vendor Solution
IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsPortierisv0.14.3Download v0.14.3 https://github.com/IBM/portieris/releases/tag/v0.14.3 .
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284125 |
|
History
Wed, 19 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. | |
| Title | Portieris is vulnerable to Image Policy Bypass via Unvalidated ownerReference | |
| First Time appeared |
Ibm
Ibm portieris |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:ibm:portieris:0.14.2:*:*:*:*:*:*:* cpe:2.3:a:ibm:portieris:0.5.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm portieris |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-19T20:29:10.276Z
Reserved: 2026-07-31T21:11:28.140Z
Link: CVE-2026-18544
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization