CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73137

highCVSS 7.7covered by 1 sourcefirst seen 2026-08-20
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the secretRef.Namespace field. This allows the GetSecret() function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure.

⚡ Watch CVE-2026-73137

Get an email if CVE-2026-73137 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73137

CVE.org record

Embed the live status

CVE-2026-73137 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73137 status](https://www.csirts.com/badge/CVE-2026-73137)](https://www.csirts.com/cve/CVE-2026-73137)