CVE-2026-73834: Red Hat Advanced Cluster Management For Kubernetes 2.11
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263322 (fixed in 1787263322)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787260453 (fixed in 1787260453)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787189811 (fixed in 1787189811)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238730 (fixed in 1787238730)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787234748 (fixed in 1787234748)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787228698 (fixed in 1787228698)
Published 2026-08-18. Last modified 2026-09-05.