PatchSiren cyber security CVE debrief
CVE-2026-73137 Red Hat CVE debrief
The multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) is vulnerable to a flaw that allows tenants with HelmRelease create permissions to manipulate the `secretRef.Namespace` field. This manipulation can lead to the `GetSecret()` function in the HelmRelease controller fetching sensitive credentials from any namespace. These credentials are then sent to an attacker-controlled Helm repository, potentially resulting in credential exfiltration from arbitrary namespace Secrets. The vulnerability has a CVSS score of 7.7, indicating high severity. Organizations using RHACM should assess their exposure and take steps to mitigate potential credential exfiltration. Specifically, those with tenants that have HelmRelease create permissions should review and restrict these permissions, monitor for suspicious activity related to credential exfiltration, and implement compensating controls to protect sensitive credentials.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-08-27
Who should care
Organizations using Red Hat Advanced Cluster Management (RHACM) should be aware of this vulnerability and assess their exposure. Specifically, those with tenants that have HelmRelease create permissions should take steps to mitigate potential credential exfiltration.
Technical summary
The multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) is vulnerable to a flaw that allows tenants with HelmRelease create permissions to manipulate the `secretRef.Namespace` field. This manipulation can lead to the `GetSecret()` function in the HelmRelease controller fetching sensitive credentials from any namespace. These credentials are then sent to an attacker-controlled Helm repository, potentially resulting in credential exfiltration from arbitrary namespace Secrets.
Defensive priority
Organizations using Red Hat Advanced Cluster Management (RHACM) should assess their exposure and take steps to mitigate potential credential exfiltration.
Recommended defensive actions
- Review and restrict HelmRelease create permissions in RHACM
- Monitor for suspicious activity related to credential exfiltration
- Implement compensating controls to protect sensitive credentials
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-73137 record indicates a flaw in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can manipulate the `secretRef.Namespace` field to fetch sensitive credentials from any namespace. These credentials are then sent to an attacker-controlled Helm repository, leading to potential credential exfiltration from arbitrary namespace Secrets. The CVSS score is 7.7, indicating a high severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73137 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73137
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73137 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73137
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-73137
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.