CVE-2026-75485
Awaiting Analysis Awaiting Analysis - Queue

Red Hat ACM Must-Gather Proxy Credential Exposure

Vulnerability report for CVE-2026-75485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-05

Assigner: redhat-SADP

Description

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-05
Generated
2026-09-07
AI Q&A
2026-08-18
EPSS Evaluated
2026-09-06
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat advanced_cluster_management_for_kubernetes *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the must-gather tool in Red Hat Advanced Cluster Management for Kubernetes. When gathering cluster data, Proxy objects are dumped in raw form, bypassing normal redaction. This exposes proxy basic-auth credentials in the must-gather archive, potentially revealing sensitive authentication details to anyone with access to the archive.

Detection Guidance

Check must-gather archives for raw Proxy objects containing basic-auth credentials. Inspect logs for unredacted proxy authentication details. Review cluster Proxy configurations for exposed sensitive fields.

Impact Analysis

If you use must-gather in your environment, sensitive proxy credentials could be exposed in the gathered data. Unauthorized individuals with access to the archive might use these credentials to gain access to your systems, leading to potential data breaches or unauthorized actions within your cluster.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. Exposure of credentials may result in data breaches, triggering mandatory breach notifications and potential fines for non-compliance with data protection regulations.

Mitigation Strategies

Restrict access to must-gather archives to authorized personnel only. Manually inspect and redact proxy basic-auth credentials before sharing archives. Update Red Hat Advanced Cluster Management for Kubernetes to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart