{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/portieris-0.5.0-0.14.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-18544"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Portieris (0.5.0-0.14.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","kubernetes","ibm","security-policy"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Portieris, an admission controller for Kubernetes designed to enforce image security policies, contains a vulnerability (CVE-2026-18544) in versions 0.5.0 through 0.14.2. This flaw stems from improper authorization of pod owner references, classified under CWE-862 (Missing Authorization).\u003c/p\u003e\n\u003cp\u003eThe vulnerability allows a remote authenticated user with access to the cluster to circumvent configured image security policies. By manipulating the pod owner references during deployment requests, an attacker can trick the admission controller into bypassing checks that would normally prevent the execution of unauthorized or non-compliant container images. This effectively neutralizes the security controls intended to ensure only verified, trusted images are run within the Kubernetes environment, potentially allowing the execution of malicious or vulnerable code.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 base score of 8.1, reflecting its high impact on confidentiality and integrity. If successfully exploited, an attacker could deploy arbitrary images that violate organizational security posture, facilitating unauthorized access or persistence within the containerized infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security update provided by IBM in the official support bulletin to address CVE-2026-18544.\u003c/li\u003e\n\u003cli\u003eAudit existing Kubernetes admission controller configurations to ensure that pod owner references are strictly validated.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes audit logs for suspicious or unauthorized image deployment attempts that bypass expected policy enforcement.\u003c/li\u003e\n\u003cli\u003eEnsure Kubernetes RBAC is restricted to limit the ability of authenticated users to modify pod specifications or influence pod owner references.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:39:39Z","date_published":"2026-08-19T22:39:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-portieris-policy-bypass/","summary":"IBM Portieris versions 0.5.0 through 0.14.2 contain a missing authorization vulnerability that allows authenticated attackers to bypass image policy enforcement by manipulating pod owner references.","title":"IBM Portieris Image Policy Enforcement Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-portieris-policy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Portieris (0.5.0-0.14.2)","version":"https://jsonfeed.org/version/1.1"}