CVE-2026-73122: Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel namespace on the hub, potentially exposing credentials for other tenants' Git and Helm repositories. This could lead to significant information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73122?
The severity of CVE-2026-73122 is rated high with a score of 7.7.
How do I fix CVE-2026-73122?
To mitigate CVE-2026-73122, review and adjust the role permissions granted to managed-cluster agents in your channel namespaces.
What impact does CVE-2026-73122 have on my system?
CVE-2026-73122 allows compromised agents to access sensitive information, including all Secrets and ConfigMaps within the channel namespaces.
Who is affected by CVE-2026-73122?
CVE-2026-73122 affects users of the multicloud-operators-channel component within Red Hat Advanced Cluster Management.
Is CVE-2026-73122 related to any specific Red Hat product?
Yes, CVE-2026-73122 is specifically related to the multicloud-operators-channel in Red Hat Advanced Cluster Management (RHACM).