Description
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.
Published: 2026-08-12
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Red Hat Advanced Cluster Management for Kubernetes 2’s multicloud-operators-channel component allows an agent belonging to a compromised managed cluster to obtain read permissions for all Secrets and ConfigMaps in every Channel namespace on the hub. This excessive role grants the ability to expose credentials for other tenants’ Git and Helm repositories, leading to significant information disclosure.

Affected Systems

The vulnerability affects Red Hat Advanced Cluster Management for Kubernetes 2, specifically the multicloud-operators-channel component. No additional product patch levels are listed in the CVE data; any version of the component that lacks the fix is vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity risk. The EPSS score of less than 1% suggests that real-world exploitation is rare but not impossible. The vulnerability is not listed in CISA KEV. The likely attack path is a compromised cluster agent exercising its granted permissions, potentially after lateral movement into the hub environment. Once in place, the agent can read sensitive configuration data, compromising tenant confidentiality. The weakness is classified as CWE‑269, indicating an improper elevation of privilege through over‑permissive role assignments.

Generated by OpenCVE AI on August 12, 2026 at 15:02 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the vendor‑released hotfix or upgrade Red Hat Advanced Cluster Management for Kubernetes to a version that removes the overly permissive role from managed cluster agents.
  • Reconfigure the multicloud-operators-channel role to follow the principle of least privilege, ensuring agents only receive secrets:get, list, watch on namespaces they require, or remove the permissions entirely.
  • Enable and monitor audit logs for secret and config map access on the hub to detect and respond to unauthorized reads.

Generated by OpenCVE AI on August 12, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 12 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.
Title Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces
First Time appeared Redhat
Redhat acm
Weaknesses CWE-269
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-27T02:16:55.333Z

Reserved: 2026-08-11T17:40:07.975Z

Link: CVE-2026-73122

cve-icon Vulnrichment

Updated: 2026-08-12T15:16:12.367Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T02:16:38.330

Modified: 2026-08-27T04:16:49.163

Link: CVE-2026-73122

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-73122 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:20:26Z

Weaknesses
  • CWE-269

    Improper Privilege Management