A flaw was found in the must-gather component of Red Hat...
Moderate severity
Unreviewed
Published
Aug 18, 2026
to the GitHub Advisory Database
•
Updated Aug 27, 2026
Description
Published by the National Vulnerability Database
Aug 18, 2026
Published to the GitHub Advisory Database
Aug 18, 2026
Last updated
Aug 27, 2026
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.
References