PT-2026-78558 · Unknown · Volsync-Addon-Controller
CVE-2026-18874
·
Published
2026-08-19
·
Updated
2026-08-27
CVSS v3.1
6.2
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
volsync-addon-controller (affected versions not specified)
Description
A flaw exists that allows the injection of malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This occurs because annotation values are not properly escaped when rendered into YAML. This issue specifically affects systems where the
volsync-addon-deploy-type: olm annotation is enabled. Successful exploitation could result in unauthorized modification or control over OLM Subscription configurations, which may impact software management within the cluster.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Volsync-Addon-Controller