<Vulnerability name="CVE-2026-75485">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-18T14:30:00</PublicDate>
    <Bugzilla id="2517905" url="https://bugzilla.redhat.com/show_bug.cgi?id=2517905" xml:lang="en:us">
must-gather: /tmp/kubeconfig retention
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>5.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-532</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.
    </Details>
    <Statement xml:lang="en:us">
This flaw in the ACM must-gather tool causes the cluster Proxy object to be collected without redaction, bypassing the sanitization provided by oc inspect. Proxy basic-auth credentials are exposed in the resulting archive, which may be shared with support teams or stored externally.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate the risk of credential exposure, restrict access to must-gather archives to authorized personnel only. Before sharing must-gather archives, especially with external entities, manually inspect and redact any sensitive information, including proxy basic-auth credentials, from the `cluster Proxy object` within the archive.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.11::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.11</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60387">RHSA-2026:60387</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787263322</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.13::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.13</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60390">RHSA-2026:60390</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787260453</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.14::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.14</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60388">RHSA-2026:60388</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787189811</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.15::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.15</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60389">RHSA-2026:60389</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787238730</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.16::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.16</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60391">RHSA-2026:60391</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787234748</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:acm:2.17::el9">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2.17</ProductName>
        <ReleaseDate>2026-08-26T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:60386">RHSA-2026:60386</Advisory>
        <Package name="rhacm2/acm-must-gather-rhel9">rhacm2/acm-must-gather-rhel9:1787228698</Package>
    </AffectedRelease>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-75485
https://nvd.nist.gov/vuln/detail/CVE-2026-75485
    </References>
</Vulnerability>