Description
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure.
Published: 2026-08-20
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the multicloud-operators-subscription component allows a tenant who can create HelmRelease objects to modify the secretRef.Namespace field. By doing so, the GetSecret() function inside the HelmRelease controller retrieves sensitive credentials from any namespace and sends them to an attacker‑controlled Helm repository, exposing arbitrary namespace secrets. The primary consequence is the exfiltration of credentials, which constitutes information disclosure and can enable further compromise of cluster resources.

Affected Systems

Red Hat Advanced Cluster Management for Kubernetes version 2, specifically the multicloud-operators-subscription component. No specific patch version is listed, so the vulnerability applies to any installation of this component in the 2.x line until a fixed release becomes available.

Risk and Exploitability

The vulnerability scores a CVSS of 7.7, indicating high severity. The EPSS score is not available, but the lack of KEV listing suggests no active exploitation reports yet. The attack requires a user with HelmRelease create permissions and cluster‑level access, making it an insider or compromised‑account vector. Once enabled, the attacker can extract any secret from any namespace and exfiltrate it to a remote repository.

Generated by OpenCVE AI on August 21, 2026 at 01:18 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a Red Hat Advanced Cluster Management for Kubernetes release that fixes the cross‑namespace secret exfiltration in multicloud-operators-subscription
  • Restrict HelmRelease creation rights to trusted principals and enforce a policy that disallows secretRef.Namespace values that reference namespaces outside the tenant's scope
  • Audit and monitor HelmRelease creation events for unexpected namespace references or outbound connections to external Helm repositories

Generated by OpenCVE AI on August 21, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Vendors & Products Redhat advanced Cluster Management For Kubernetes

Thu, 20 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure.
Title Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secret exfiltration via helmrelease.repo.secretref.namespace
First Time appeared Redhat
Redhat acm
Weaknesses CWE-200
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-05T14:24:51.220Z

Reserved: 2026-08-11T17:40:07.955Z

Link: CVE-2026-73137

cve-icon Vulnrichment

Updated: 2026-08-21T15:42:22.028Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T21:17:09.270

Modified: 2026-08-28T21:17:10.720

Link: CVE-2026-73137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:00:43Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor