CVE-2026-18544: Portieris is vulnerable to Image Policy Bypass via Unvalidated ownerReference
IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.
Other sources
IBM Portieris could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Portieristo a version that resolves this vulnerability.Fixed in 0.14.3
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker must be remotely authenticated. No user interaction is required, and the attack complexity is low.
Which deployments are known to be affected?
IBM Portieris versions 0.5.0 through 0.14.2 are identified as affected.
What is the security impact of successful exploitation?
A successful attacker can bypass image policy enforcement through improperly authorized pod owner references. The reported impact includes high confidentiality and integrity impact, with no availability impact reported.