PT-2026-78558 · Unknown · Volsync-Addon-Controller

CVE-2026-18874

·

Published

2026-08-19

·

Updated

2026-08-27

CVSS v3.1

6.2

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions volsync-addon-controller (affected versions not specified)
Description A flaw exists that allows the injection of malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This occurs because annotation values are not properly escaped when rendered into YAML. This issue specifically affects systems where the volsync-addon-deploy-type: olm annotation is enabled. Successful exploitation could result in unauthorized modification or control over OLM Subscription configurations, which may impact software management within the cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18874

Affected Products

Volsync-Addon-Controller