Skip to content
Threat Feed
high advisory

CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management

A vulnerability in the multicloud-operators-channel component of Red Hat Advanced Cluster Management allows compromised agents to perform unauthorized reads of Secrets and ConfigMaps within hub Channel namespaces, risking credential exposure.

CVE search metadata

CVE search record: CVE-2026-73122. Severity: high. CVSS: 7.7. KEV: no. Product: Advanced Cluster Management. Brief: CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management. Brief link: https://feed.craftedsignal.io/briefs/2026-08-rhacm-vulnerability/

CVE-2026-73122 describes a security flaw within the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability enables a compromised agent originating from a managed cluster to exceed its intended scope and gain unauthorized access to sensitive data residing on the central hub. Specifically, an attacker controlling a managed cluster agent can read all Secrets and ConfigMaps associated with any Channel namespace on the hub. This potential information disclosure is critical as it may expose sensitive credentials, including authentication tokens and keys for third-party Git and Helm repositories used by other tenants within the RHACM environment. The vulnerability highlights a breakdown in namespace isolation and role-based access control (RBAC) enforcement for cluster-wide operators, necessitating immediate review of existing cluster management configurations and adherence to vendor-provided patches.

Impact

Successful exploitation of this vulnerability allows unauthorized access to sensitive configurations and credentials stored within the hub's Channel namespaces. Impacted organizations using RHACM for multi-tenant cluster orchestration may face large-scale credential theft across Git and Helm repository integrations. This unauthorized access can subsequently lead to secondary compromises of supply chain pipelines or production application repositories managed by the exposed credentials.

Recommendation

  • Monitor RHACM hub logs for anomalous API access patterns or unauthorized read requests targeting Secrets and ConfigMaps within Channel namespaces.
  • Apply the security patches provided by Red Hat to remediate CVE-2026-73122 across all Advanced Cluster Management installations.
  • Audit and restrict RBAC permissions for managed cluster service accounts to the minimum necessary level, following the principle of least privilege.

Immediate actions

Patch CVE-2026-73122 on all Red Hat Advanced Cluster Management hubs

IT Operations 48h

Mitigations

Audit RBAC permissions and namespace access for cluster agents

immediate Security Engineering

CVE-2026-73122