---
id: CVE-2026-18874
title: A flaw was found in volsync-addon-controller
summary: >-
  A flaw was found in volsync-addon-controller. This vulnerability allows an
  attacker to inject malicious YAML (Yet Another Markup Language) code into the
  OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to
  improper esc…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-94
vendor: Red Hat
product: rhacm2/acm-volsync-addon-controller-rhel9
affected:
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
  - rhacm2/acm-volsync-addon-controller-rhel9 (all versions)
patched:
  - advanced_cluster_management_for_kubernetes 2.11
  - advanced_cluster_management_for_kubernetes 2.13
  - advanced_cluster_management_for_kubernetes 2.14
  - advanced_cluster_management_for_kubernetes 2.15
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_management_for_kubernetes 2.17
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T22:17:42.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18874'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:60386'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60387'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60388'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60389'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60390'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:60391'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-18874'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2511115'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-18874.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-18874'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18874'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-19T19:54:04.444241Z'
epss: 0.00538
epssPercentile: 0.42804
ingestedAt: '2026-09-05T19:43:55.276Z'
---

## Overview

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:60387** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.11 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60387)
- **RHSA-2026:60390** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60390)
- **RHSA-2026:60388** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60388)
- **RHSA-2026:60389** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60389)
- **RHSA-2026:60391** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60391)
- **RHSA-2026:60386** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.17 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60386)
