CVE-2026-73834: Red Hat Advanced Cluster Management For Kubernetes 2.11

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.

Affected products

  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263322 (fixed in 1787263322)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787260453 (fixed in 1787260453)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787189811 (fixed in 1787189811)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238730 (fixed in 1787238730)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787234748 (fixed in 1787234748)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787228698 (fixed in 1787228698)

Published 2026-08-18. Last modified 2026-09-05.