CVE-2026-18544: IBM Portieris

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.

Affected products

  • IBM Portieris: from 0.5.0, before 0.14.3 (fixed in 0.14.3)

Published 2026-08-19. Last modified 2026-09-02.