Information Disclosure Vulnerability in Red Hat Advanced Cluster Management
CVE-2026-73137

7.7HIGH

What is CVE-2026-73137?

A vulnerability exists within the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This issue arises when a tenant with HelmRelease creation permissions manipulates the secretRef.Namespace field, enabling the GetSecret() function in the HelmRelease controller to retrieve sensitive credentials from any namespace. Consequently, these credentials can be transmitted to an attacker-controlled Helm repository, allowing for the potential exfiltration of secrets from arbitrary namespaces, which presents a significant risk for sensitive data disclosure.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263584

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787263693

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787170830

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.