Sceawere

Vulnerability Detail

CVE-2026-73122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RHACM Channel Unauthorized Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
Red Hat
Product
Red Hat Advanced Cluster Management for Kubernetes 2
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-12T02:16:38.330Z",
  "pubdate": "2026-08-12T02:16:38.330Z",
  "executiveSummary": "A critical unauthorized information disclosure vulnerability has been identified within the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This security flaw permits a compromised agent originating from a managed cluster to bypass authorization boundaries and gain unauthorized read access to sensitive cluster resources. Specifically, the affected agent can retrieve all Secrets and ConfigMaps residing within any Channel namespace located on the hub cluster.\nThe potential impact of this vulnerability is severe, as the exposed Secrets and ConfigMaps frequently contain sensitive authentication material, including credentials for other tenants' Git and Helm repositories. An attacker who has compromised a managed cluster agent can leverage these exposed credentials to pivot across multi-tenant environments, potentially compromising external repositories and connected infrastructure.\nThe attack vector relies on compromised agent capabilities within the managed cluster ecosystem, which subsequently abuse overly permissive access controls on the hub cluster's Channel namespaces. Exploitation requires prior compromise of a managed cluster agent to interact with the multicloud-operators-channel component, after which the adversary can systematically harvest sensitive credentials and configuration data without triggering standard access restrictions.",
  "technicalDetails": "The vulnerability resides in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM), specifically within the authorization and namespace scoping logic governing interactions between managed cluster agents and the hub cluster. The root cause stems from insufficient access control enforcement, which fails to properly restrict the operational scope of managed cluster agents.\nUnder normal operating conditions, agents deployed on managed clusters require limited access to synchronize resources via designated channels. However, due to the flaw in the multicloud-operators-channel component, a compromised agent can issue API requests that transcend its intended administrative boundaries. The vulnerable component improperly permits these agents to read arbitrary Kubernetes Secrets and ConfigMaps across any Channel namespace instantiated on the hub cluster.\nThe step-by-step attack flow proceeds as follows: First, an attacker compromises an agent operating within a managed cluster, gaining control over its local execution context and API client capabilities. Second, the attacker utilizes the compromised agent to send read requests targeting Channel namespaces on the hub cluster. Third, due to the lack of strict namespace isolation and privilege validation within the multicloud-operators-channel component, the hub cluster processes and fulfills the requests. Fourth, the agent receives the contents of sensitive Secrets and ConfigMaps belonging to other tenants or channels.\nThe post-exploitation impact includes the extraction of high-value authentication artifacts. Because Channel namespaces commonly store repository synchronization parameters, the harvested Secrets and ConfigMaps frequently contain plaintext or weakly encoded credentials for external Git and Helm repositories. Armed with these credentials, the attacker achieves cross-tenant information exposure and can potentially compromise external software supply chains and proprietary codebases associated with other tenants managed by the RHACM hub."
}
CVE-2026-73122: RHACM Channel Unauthorized Information Disclosure (HIGH Severity, CVSS: 7.7) - Sceawere