Database/Container, Kubernetes & orchestration
RHACM multicloud-operators-channel: managed-cluster agent reads all Secrets in hub Channel namespaces
Impact
A single compromised managed cluster gets to read every Secret and ConfigMap in any Channel namespace on the RHACM hub, which is where the Git and Helm repository credentials for all the other managed clusters are kept. In a fleet where RHACM governs several GPU clusters for different tenants or business units, one foothold on the weakest cluster yields the deployment credentials for the rest, and those credentials typically allow pushing manifests that land as running workloads on GPU nodes. Red Hat scores it scope-changed (S:C) for exactly that reason: the disclosure crosses the boundary between the compromised cluster and the hub. Confidentiality only - the flaw does not by itself let the agent write to the hub.
Who can reach it
An attacker who already controls the RHACM agent on any single managed cluster, authenticated to the hub with that agent's own low-privilege credentials. No hub administrator access and no user interaction required.
What to do
Apply the RHSA errata matching your RHACM version (2.11 through 2.17 are all listed); this updates the hub multicloud-operators-channel controller and requires a rolling restart of the hub operator pods, not a node reboot. Because the exposure is credential disclosure, patching alone is not enough on a cluster you believe was already compromised: rotate the Git and Helm repository credentials stored in Channel namespaces afterwards.
References
Related entries
- RHACM subscription controller: HelmRelease secretRef.Namespace reads Secrets from any namespaceCVE-2026-73137 · Red Hat Advanced Cluster Management multicloud-operators-subscription (HelmRelease secretRef)High
- KubeVirt: Symlink path traversal in the virt-exportserver VMExport directory endpointCVE-2026-9804 · KubeVirtHigh
- ingress-nginx: Custom nginx snippets in an Ingress annotation retrieve the ingress-nginx service-account tokenCVE-2021-25742 · ingress-nginxHigh
- ingress-nginx: Ingress `path` can be pointed at the service-account token fileCVE-2021-25745 · ingress-nginxHigh
- ingress-nginx: Directive injection through Ingress annotations obtains controller credentialsCVE-2021-25746 · ingress-nginxHigh
- ingress-nginx: Newline character bypasses `path` sanitizationCVE-2021-25748 · ingress-nginxHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.