CVE-2026-18874

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.11 security update

Beschreibung

Ein Fehler wurde in volsync-addon-controller gefunden. Diese Schwachstelle ermöglicht es einem Angreifer, bösartigen YAML-Code (Yet Another Markup Language) in die OpenShift Lifecycle Manager (OLM) Subscription-Ressource einzuschleusen. Dies liegt an der fehlerhaften Entschlüsselung von Annotation-Werten beim Rendern in YAML. Eine erfolgreiche Ausnutzung könnte zu unbefugter Änderung oder Kontrolle über OLM-Subscription-Konfigurationen führen, was potenziell die Softwareverwaltung im Cluster beeinträchtigen kann. Dieses Problem betrifft hauptsächlich Systeme, bei denen die Annotation 'volsync-addon-deploy-type: olm' explizit aktiviert ist.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.2
Quelle: nvd-v3
36.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-26 20:11 UTC
CWE-94

Weakness-Klassen (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 22:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18874.json">CVE-2026-18874</a>
  2. CVE Modified2026-09-08 14:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18874.json">CVE-2026-18874</a>
  3. CVE Modified2026-09-05 17:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18874.json">CVE-2026-18874</a>
  4. CVE Modified2026-09-05 15:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18874.json">CVE-2026-18874</a>
  5. CVE Modified2026-08-26 23:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18874.json">CVE-2026-18874</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:60386
    • Reference: https://access.redhat.com/errata/RHSA-2026:60389
    • Reference: https://access.redhat.com/errata/RHSA-2026:60390

Betroffene Betriebssysteme

  • windows

    microsoft / windows_10_1607

  • windows

    microsoft / windows_10_1809

  • windows

    microsoft / windows_10_21h2

  • windows

    microsoft / windows_10_22h2

  • windows

    microsoft / windows_11_23h2

  • windows

    microsoft / windows_11_24h2

  • windows

    microsoft / windows_11_25h2

  • windows

    microsoft / windows_11_26h1

  • windows

    microsoft / windows_server_2012r2

  • windows

    microsoft / windows_server_2012

  • windows

    microsoft / windows_server_2016

  • windows

    microsoft / windows_server_2019

  • windows

    microsoft / windows_server_2022

  • windows

    microsoft / windows_server_2025

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    cloudstack4.15.0.0 – 4.20.3.1

  • apache

    cloudstack4.21.0.0 – 4.22.1.1

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • axios

    axios0.31.1 – 0.33.0

  • axios

    axios1.15.1 – 1.18.0

  • bitnami

    golang1.26.0-0

  • bitnami

    grafana12.0.0

  • bitnami

    grafana12.3.0

  • bitnami

    grafana12.4.0

  • bitnami

    grafana13.0.0

  • bitnami

    grafana8.5.0

  • bitnami

    thrift

  • go

    go.opentelemetry.io/otel1.41.0

  • go

    go.opentelemetry.io/otel1.43.0

Quellen & Referenzen

Verknüpfte CVEs

32 weitere CVEs anzeigen
IDCVE-2026-18874