<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Rhacm - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/rhacm/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 03:55:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/rhacm/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management</title><link>https://feed.craftedsignal.io/briefs/2026-08-rhacm-vulnerability/</link><pubDate>Wed, 12 Aug 2026 03:55:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-rhacm-vulnerability/</guid><description>A vulnerability in the multicloud-operators-channel component of Red Hat Advanced Cluster Management allows compromised agents to perform unauthorized reads of Secrets and ConfigMaps within hub Channel namespaces, risking credential exposure.</description><content:encoded><![CDATA[<p>CVE-2026-73122 describes a security flaw within the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability enables a compromised agent originating from a managed cluster to exceed its intended scope and gain unauthorized access to sensitive data residing on the central hub. Specifically, an attacker controlling a managed cluster agent can read all Secrets and ConfigMaps associated with any Channel namespace on the hub. This potential information disclosure is critical as it may expose sensitive credentials, including authentication tokens and keys for third-party Git and Helm repositories used by other tenants within the RHACM environment. The vulnerability highlights a breakdown in namespace isolation and role-based access control (RBAC) enforcement for cluster-wide operators, necessitating immediate review of existing cluster management configurations and adherence to vendor-provided patches.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized access to sensitive configurations and credentials stored within the hub's Channel namespaces. Impacted organizations using RHACM for multi-tenant cluster orchestration may face large-scale credential theft across Git and Helm repository integrations. This unauthorized access can subsequently lead to secondary compromises of supply chain pipelines or production application repositories managed by the exposed credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor RHACM hub logs for anomalous API access patterns or unauthorized read requests targeting Secrets and ConfigMaps within Channel namespaces.</li>
<li>Apply the security patches provided by Red Hat to remediate CVE-2026-73122 across all Advanced Cluster Management installations.</li>
<li>Audit and restrict RBAC permissions for managed cluster service accounts to the minimum necessary level, following the principle of least privilege.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-security</category><category>rhacm</category><category>cve-2026-73122</category></item></channel></rss>