Red HatCVE-2026-73122
Red Hat multicloud-operators-channel: information disclosure
High7.7CVE-2026-73122 · Published Aug 12, 2026 · updated Aug 27, 2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
- www.cve.org/CVERecord?id=CVE-2026-73122
- nvd.nist.gov/vuln/detail/CVE-2026-73122
- access.redhat.com/errata/RHSA-2026:60386
- access.redhat.com/errata/RHSA-2026:60387
- access.redhat.com/errata/RHSA-2026:60388
- access.redhat.com/errata/RHSA-2026:60389
- access.redhat.com/errata/RHSA-2026:60390
- access.redhat.com/errata/RHSA-2026:60391
- access.redhat.com/security/cve/CVE-2026-73122
- bugzilla.redhat.com/show_bug.cgi?id=2514230
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Red Hat: mass assignment | High8.5 | No fix yet |
| Aug 12 | Red Hat insights-client. The: excessive privileges | Medium6.5 | No fix yet |
| Aug 12 | Red Hat search-v2-api: denial of service | High7.5 | No fix yet |
| Aug 12 | Red Hat acm-search-v2-rhel9: remote code execution | Critical9.0 | No fix yet |
| Aug 12 | Red Hat open-iscsi. This vulnerability: denial of service | Medium6.5 | No fix yet |
| Aug 12 | Red Hat open-iscsi: integer overflow | Medium6.5 | No fix yet |