Security Advisory

CVE-2026-73834

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 15:15:38
Last updated 2026-08-20 14:08:28
Assigner redhat
CVSS score 5.5
State PUBLISHED

Description

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.