Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18874— Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription

Quick assessment

Affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 volsync-addon-controller 中发现了一个漏洞。该漏洞允许攻击者向 OpenShift 生命周期管理器(OLM)的 Subscription 资源中注入恶意的 YAML(另一种标记语言)代码。这是由于在将注解值渲染为 YAML 时,对其进行了不正确的转义处理。成功利用此漏洞可能导致攻击者未经授权地修改或控制 OLM Subscription 的配置,进而可能影响集群内的软件管理。此问题主要影响那些显式启用了 注解的系统。

CVSS 6.2 · Medium EPSS 0.30% · P22

Possible ATT&CK Techniques 1 AI

T1195.002 · Compromise Software Supply Chain

Affected Version Matrix 1

VendorProduct Version RangeStatus
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18874

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.11 1787683560 ~ * cpe:/a:redhat:acm:2.11::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.13 1787266564 ~ * cpe:/a:redhat:acm:2.13::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.14 1787266564 ~ * cpe:/a:redhat:acm:2.14::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.15 1787266360 ~ * cpe:/a:redhat:acm:2.15::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.16 1787266564 ~ * cpe:/a:redhat:acm:2.16::el9
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2.17 1787266556 ~ * cpe:/a:redhat:acm:2.17::el9

II. Public POCs for CVE-2026-18874

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18874

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18874 (3)

Other References for CVE-2026-18874 (5)

Same Patch Batch · Red Hat · 2026-08-19 · 10 CVEs total

CVE-2026-70496 9.9 CRITICAL Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v
CVE-2026-66794 9.3 CRITICAL Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste
CVE-2026-71470 9.1 CRITICAL Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow uns
CVE-2026-76139 8.0 HIGH Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m
CVE-2026-75569 7.7 HIGH Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu
CVE-2026-76235 7.5 HIGH Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie
CVE-2026-76827 6.8 MEDIUM Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c
CVE-2026-75900 6.1 MEDIUM Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size
CVE-2026-76166 4.3 MEDIUM Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast

IV. Related Vulnerabilities

V. Comments for CVE-2026-18874

No comments yet


Leave a comment