CVE-2026-75485: Red Hat Advanced Cluster Management For Kubernetes 2.11
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787263322 (fixed in 1787263322)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787260453 (fixed in 1787260453)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787189811 (fixed in 1787189811)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238730 (fixed in 1787238730)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787234748 (fixed in 1787234748)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787228698 (fixed in 1787228698)
Published 2026-08-18. Last modified 2026-09-05.