CVE-2026-18381: Server-Side Request Forgery (SSRF) in Red Hat Cost Management Metrics Operator
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
AI Analysis
Technical Summary
This vulnerability in the koku-metrics-operator component of Red Hat OpenShift allows a user with edit permissions on the CostManagementMetricsConfig custom resource to specify an arbitrary URL for data upload. The operator attaches its Kubernetes service-account bearer token to requests sent to this URL, enabling the attacker to obtain the token. This SSRF flaw can lead to token disclosure, potentially allowing further privilege escalation or unauthorized access within the cluster. The CVSS 3.1 base score is 7.6, reflecting network attack vector, low attack complexity, required privileges, no user interaction, scope change, high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation level is indicated in the vendor advisory as of the published date.
Potential Impact
An attacker with edit permissions on the CostManagementMetricsConfig custom resource can exploit this vulnerability to obtain the Kubernetes service-account bearer token used by the operator. This token disclosure can lead to unauthorized access or privilege escalation within the OpenShift cluster. The confidentiality impact is high, while integrity impact is low and availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-18381 for current remediation guidance. Until an official fix is available, restrict edit permissions on the CostManagementMetricsConfig custom resource to trusted users only to reduce risk.
CVE-2026-18381: Server-Side Request Forgery (SSRF) in Red Hat Cost Management Metrics Operator
Description
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
CVSS v3.1
Score 7.6high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in the koku-metrics-operator component of Red Hat OpenShift allows a user with edit permissions on the CostManagementMetricsConfig custom resource to specify an arbitrary URL for data upload. The operator attaches its Kubernetes service-account bearer token to requests sent to this URL, enabling the attacker to obtain the token. This SSRF flaw can lead to token disclosure, potentially allowing further privilege escalation or unauthorized access within the cluster. The CVSS 3.1 base score is 7.6, reflecting network attack vector, low attack complexity, required privileges, no user interaction, scope change, high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation level is indicated in the vendor advisory as of the published date.
Potential Impact
An attacker with edit permissions on the CostManagementMetricsConfig custom resource can exploit this vulnerability to obtain the Kubernetes service-account bearer token used by the operator. This token disclosure can lead to unauthorized access or privilege escalation within the OpenShift cluster. The confidentiality impact is high, while integrity impact is low and availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-18381 for current remediation guidance. Until an official fix is available, restrict edit permissions on the CostManagementMetricsConfig custom resource to trusted users only to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-30T11:37:06.496Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18381","vendor":"Red Hat"}]
Threat ID: 6a6b3ea09c2644c7f80a42e8
Added to database: 07/30/2026, 12:08:00 UTC
Last enriched: 07/30/2026, 12:22:03 UTC
Last updated: 07/30/2026, 12:52:41 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.