Product
high
advisory
Information Disclosure in Red Hat Advanced Cluster Management via HelmRelease Manipulation
1 TTP 1 CVEAn authenticated user with HelmRelease creation permissions can exploit CVE-2026-73137 to exfiltrate sensitive credentials from arbitrary Kubernetes namespaces in Red Hat Advanced Cluster Management.
Advanced Cluster Management
exfiltration
vulnerability
cloud
kubernetes
1t
1c
high
advisory
CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management
1 TTP 1 CVEA vulnerability in the multicloud-operators-channel component of Red Hat Advanced Cluster Management allows compromised agents to perform unauthorized reads of Secrets and ConfigMaps within hub Channel namespaces, risking credential exposure.
Advanced Cluster Management
vulnerability
cloud-security
rhacm
cve-2026-73122
1t
1c
critical
advisory
Red Hat Advanced Cluster Management and Multicluster Engine Vulnerability Allows Remote Code Execution or DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in Red Hat Advanced Cluster Management and Multicluster engine for Kubernetes to execute arbitrary program code or cause a denial of service condition.
Advanced Cluster Management +1
kubernetes
rce
dos
redhat
2r
2t