Bug 2517904 (CVE-2026-73834) - CVE-2026-73834 must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction
Summary: CVE-2026-73834 must-gather: must-gather: embedded Secret data in ACM wrapper ...
Keywords:
Status: NEW
Alias: CVE-2026-73834
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-18 14:29 UTC by Christopher Lusk
Modified: 2026-08-18 14:36 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Christopher Lusk 2026-08-18 14:29:31 UTC
The ACM must-gather tool collects certain ACM "wrapper" Custom Resources that embed Secret data (credentials, tokens) without applying redaction. When an administrator runs must-gather for troubleshooting, these secrets are captured in cleartext in the must-gather archive. Archives are routinely uploaded to support cases, exposing credentials to anyone with access to the archive.

Source: Project Glasswing AI-SAST audit of stolostron/must-gather.
Jira: ACM-38732
Remediation: Fix branch glasswing/f001/embedded-secret-data-in-acm-wrapper-crs (commit 2f863307b468), checks_passed.
Reporter: Justin Kulikauskas


Note You need to log in before you can comment on or make changes to this bug.