Data Exposure Vulnerability in Red Hat Advanced Cluster Management for Kubernetes
CVE-2026-73834

5.5MEDIUM

What is CVE-2026-73834?

A flaw exists in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes, which causes certain ACM wrapper Custom Resources to collect Secret data without proper redaction. As a result, when administrators execute must-gather, sensitive credentials and tokens may be archived in cleartext, posing a risk of unauthorized access to confidential information for anyone who obtains the archive.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787263322

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787260453

Red Hat Advanced Cluster Management for Kubernetes 2.14 1787189811

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.