Junglewise Threat Intelligence

CVE-2026-73137: Red Hat Advanced Cluster Management credential exfiltration in HelmRelease controller

CVE-2026-73137 · Severity: high · CVSS 7.7 · Published 2026-08-20

Vendors: Red Hat.

Executive brief

Red Hat Advanced Cluster Management (RHACM) is used by enterprises to manage Kubernetes clusters across multiple cloud environments. A vulnerability in its HelmRelease component allows users with permission to create HelmRelease objects to extract sensitive credentials from any namespace by manipulating namespace references, potentially exposing database passwords, API keys, and other secrets stored across the platform.

Technical details

The vulnerability exists in the multicloud-operators-subscription component of RHACM, specifically in the HelmRelease controller. A tenant with HelmRelease create permissions can manipulate the `secretRef.Namespace` field to cause the `GetSecret()` function to retrieve sensitive credentials from any namespace, rather than being restricted to the current namespace. These credentials are then sent to an attacker-controlled Helm repository. The attack requires only HelmRelease create permissions and network reachability to the Helm repository; it results in information disclosure of secrets from arbitrary namespaces. A patch is available in RHACM v2.17.1 and later.

Affected products

  • Red Hat Advanced Cluster Management for Kubernetes before v2.17.1

Timeline

  • 2026-08-20: disclosed
  • 2026-08-26: advisory
  • 2026-08-26: patched: RHACM v2.17.1

References