CVE-2026-73122 – Red Hat Advanced Cluster Management for Kubernetes 2
“Broken trust boundaries can turn tenant access into cluster-wide control, code execution, and exposure of critical credentials.”
Red Hat Advanced Cluster Management for Kubernetes 2 is affected by 15 vulnerabilities spanning tenant isolation, privilege escalation, arbitrary code execution, authentication bypass, secret exposure, and denial of service. CVE-2026-70398 has a CVSS score of 9.6, Critical severity; CVE-2026-71471 has a CVSS score of 9.0, Critical severity; and CVE-2026-72508 and CVE-2026-72526 each have a CVSS score of 9.9, Critical severity. These flaws can expose spoke-cluster tokens, deploy arbitrary images or cluster-scoped resources, and compromise managed clusters.
CVE-2026-71473 has a CVSS score of 8.5, High severity; CVE-2026-66878 and CVE-2026-73122 are 7.7, High severity; and CVE-2026-71467 and CVE-2026-71469 are 7.5, High severity. The remaining six vulnerabilities are Medium severity, with CVSS scores from 5.0 to 6.5, and include credential leakage, excessive privileges, cross-namespace secret manipulation, and federated-search authorization weaknesses.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-269