Race condition in VMware Tanzu velero - #VU153052
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a race condition in pkg/repository/udmrepo/kopialib/repo_init.go. A remote attacker can exploit the race and cause one repository operation to adopt the bucket configuration and access credentials intended for a different repository/BSL.