Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.2%top 36%

Red Hat Security Advisory: Cost Management Metrics Operator Update

0
High
Published: 06/22/2026 (06/22/2026, 15:31:52 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Cost Management Metrics Operator is a component of the Red Hat Cost Managment service for Openshift. The operator runs on the latest supported versions of Openshift. This operator obtains OpenShift usage data by querying Prometheus every hour to create metric reports that it uploads to Cost Management at console.redhat.com.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected software

Affected versions
Red HatCost ManagementCost Management 4amd64registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:92da8c11452f7ae0f24e70d453f03d31e7a10ac1276c5bdc63539952d2c87b23_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 14:35:03 UTC

Technical Analysis

The Cost Management Metrics Operator in Red Hat's Cost Management service for OpenShift is affected by CVE-2026-2100, a vulnerability with a high severity rating and an impact on availability (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). The operator queries Prometheus every hour to gather usage data and uploads reports to the Red Hat Cost Management console. The Red Hat advisory (RHSA-2026:27998) provides an update to version 4.4.1 but does not specify any fixes addressing this CVE. No known exploits exist in the wild. The advisory recommends applying all previously released errata before updating the operator. The affected component runs on the latest supported OpenShift versions. No explicit patch or remediation is currently documented in the advisory.

Potential Impact

The vulnerability impacts the availability of the Cost Management Metrics Operator, potentially causing denial of service or disruption of metric reporting functionality. There is no reported impact on confidentiality or integrity. The operator's role in collecting and uploading usage metrics means that exploitation could affect the reliability of cost management data in OpenShift environments.

Mitigation Recommendations

The Red Hat advisory does not list any specific fixes or patches for CVE-2026-2100 at this time. It recommends ensuring that all previously released errata relevant to the system are applied before updating to the latest operator version (4.4.1). Users should follow Red Hat's official guidance for upgrading operators via the OpenShift Operator Lifecycle Manager. Monitor Red Hat's advisories for future updates or patches addressing this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:18143
Cve Count
1
Additional Cves
[]
Cvss Version
3.1

Threat ID: 6a16098ae29bf47b50653c9b

Added to database: 05/26/2026, 20:58:50 UTC

Last enriched: 07/30/2026, 14:35:03 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 141

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses