Description
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.
Published: 2026-08-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the must‑gather component of Red Hat Advanced Cluster Management for Kubernetes causes ACM wrapper Custom Resources that embed Secret data to be collected without redaction. When an administrator executes must‑gather, the resulting archive contains credentials and tokens in cleartext, allowing anyone who can read the archive to obtain sensitive authentication information. This can lead to unauthorized disclosure of authentication data.

Affected Systems

The vulnerability is limited to Red Hat Advanced Cluster Management for Kubernetes 2, the product identified by the CNA as affected.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium impact. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so widespread exploitation is not yet documented. The likely attack vector is an authenticated user who can run must‑gather; if the produced archive is stored or transferred, an attacker who can access it can read the exposed credentials. Because the flaw manifests during normal use of must‑gather, the risk is moderate but non‑zero.

Generated by OpenCVE AI on August 18, 2026 at 18:41 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Restrict the execution of must‑gather to a limited set of trusted administrators and roles
  • Store and handle must‑gather archives in a secure location with strict access controls
  • Perform regular audits of must‑gather archives to detect embedded credentials or tokens
  • Consider disabling the collection of ACM wrapper Custom Resources that contain secrets if the feature can be turned off
  • Monitor cluster activity for unusual must‑gather usage as a potential intrusion indicator
  • CNA workaround: mitigation is not available or options do not meet criteria

Generated by OpenCVE AI on August 18, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.11::el9
cpe:/a:redhat:acm:2.14::el9
cpe:/a:redhat:acm:2.16::el9
References

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2 cpe:/a:redhat:acm:2.13::el9
cpe:/a:redhat:acm:2.15::el9
cpe:/a:redhat:acm:2.17::el9
References

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.
Title Must-gather: must-gather: embedded secret data in acm wrapper crs collected without redaction
First Time appeared Redhat
Redhat acm
Weaknesses CWE-312
CPEs cpe:/a:redhat:acm:2
Vendors & Products Redhat
Redhat acm
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-05T17:08:28.740Z

Reserved: 2026-08-18T14:31:50.303Z

Link: CVE-2026-73834

cve-icon Vulnrichment

Updated: 2026-08-20T14:08:20.670Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T16:18:17.493

Modified: 2026-09-05T18:17:28.770

Link: CVE-2026-73834

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T14:30:00Z

Links: CVE-2026-73834 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T21:15:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information