Junglewise Threat Intelligence

CVE-2026-73122: Red Hat Advanced Cluster Management information disclosure in multicloud-operators-channel

CVE-2026-73122 · Severity: high · CVSS 7.7 · Published 2026-08-12

Vendors: Red Hat.

Executive brief

A flaw in Red Hat Advanced Cluster Management's multicloud-operators-channel component allows a compromised agent running on a managed cluster to read all secrets and configuration data from the hub cluster, potentially exposing credentials for other customers' Git and Helm repositories. This could result in unauthorized access to sensitive infrastructure configurations and tenant data breaches.

Technical details

The multicloud-operators-channel component in RHACM lacks proper access controls on Secrets and ConfigMaps stored in Channel namespaces on the hub cluster. A compromised or malicious agent deployed on a managed cluster can enumerate and read these sensitive objects, exposing credentials and configuration details belonging to other tenants. The vulnerability requires an agent to already be running on a managed cluster (a prerequisite condition), but does not require additional authentication beyond the agent's existing cluster access. The exposure includes Git and Helm repository credentials, potentially enabling lateral movement and supply-chain attacks. A patch is available in RHACM 2.17.1 as part of security advisory RHSA-2026:60386.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes versions prior to 2.17.1

Timeline

  • 2026-08-12: disclosed
  • 2026-08-26: patched: RHSA-2026:60386 released with RHACM 2.17.1

References