PatchSiren cyber security CVE debrief
CVE-2026-73834 Red Hat CVE debrief
The must-gather component of Red Hat Advanced Cluster Management for Kubernetes contains a flaw that allows certain ACM wrapper Custom Resources with embedded Secret data to be collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive. This potentially exposes sensitive information to anyone with access to the archive. The vulnerability affects administrators and users of Red Hat Advanced Cluster Management for Kubernetes, especially those with access to must-gather archives. To address this vulnerability, defenders should focus on verifying the affected scope, reviewing vendor guidance, and implementing necessary controls to prevent exploitation. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. Compensating controls, such as additional monitoring or access controls, may be necessary for exposed systems while remediation is scheduled and verified. The goal is to minimize the risk of sensitive information exposure and prevent potential security incidents. This requires a coordinated effort from various teams and stakeholders to ensure the vulnerability is properly addressed.
- Vendor
- Red Hat
- Product
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-27
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-27
Who should care
Administrators and users of Red Hat Advanced Cluster Management for Kubernetes, especially those with access to must-gather archives, should be aware of the potential for sensitive information exposure. They should prioritize verifying and mitigating the vulnerability, focusing on must-gather component usage and access controls. This includes reviewing and mitigating exposure of sensitive information in ACM wrapper Custom Resources and monitoring for and restricting access to archives generated by must-gather. Additionally, operators, platform administrators, and security teams should assess their exposure and take necessary precautions to protect their environments. Vulnerability management and security teams should also review the vulnerability and implement necessary controls to prevent exploitation. Asset inventory and monitoring teams should be aware of the potential for sensitive information exposure and take steps to detect and respond to potential security incidents. Rollback and change management teams should be prepared to quickly apply patches or mitigations if necessary. Source tracking and incident response teams should also be aware of the vulnerability and be prepared to respond quickly in case of an exploit. Compensating controls, such as additional monitoring or access controls, may be necessary for exposed systems while remediation is scheduled and verified. The goal is to minimize the risk of sensitive information exposure and prevent potential security incidents. This requires a coordinated effort from various teams and stakeholders to ensure the vulnerability is properly addressed. To achieve this, defenders should focus on verifying the affected scope, reviewing vendor guidance, and implementing necessary controls to prevent exploitation. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. By taking these steps, defenders can minimize the risk of sensitive information exposure and prevent potential security incidents. The vulnerability highlights the importance of proper access controls and monitoring for sensitive information. It also emphasizes the need for a coordinated and
Technical summary
The must-gather component of Red Hat Advanced Cluster Management for Kubernetes collects certain ACM wrapper Custom Resources without redacting embedded Secret data. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive. This vulnerability affects administrators and users of Red Hat Advanced Cluster Management for Kubernetes, especially those with access to must-gather archives.
Defensive priority
Administrators using Red Hat Advanced Cluster Management for Kubernetes should prioritize verifying and mitigating the vulnerability, focusing on must-gather component usage and access controls.
Recommended defensive actions
- Verify must-gather component usage and access controls in Red Hat Advanced Cluster Management for Kubernetes
- Review and mitigate exposure of sensitive information in ACM wrapper Custom Resources
- Monitor for and restrict access to archives generated by must-gather
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Conduct asset inventory to identify potentially affected systems
- Establish rollback and change management procedures for quick patch application if necessary
- Track exceptions and retest remediated assets to ensure vulnerability closure
Evidence notes
The CVE-2026-73834 record indicates a flaw in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes, allowing certain ACM wrapper Custom Resources with embedded Secret data to be collected without redaction. The NVD entry is currently Awaiting Analysis. Administrators should verify and mitigate the vulnerability, focusing on must-gather component usage and access controls. Evidence is limited, and further verification is required to understand the full scope of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73834 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73834
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73834 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73834
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60386
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60387
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60388
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60389
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60390
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:60391
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-73834
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.