Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-75485

CVE-2026-75485: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.5

    Medium [CVE-2026-75485] /tmp/kubeconfig retention

    CVE-2026-75485Source published Source updated

    A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive. This flaw in the ACM must-gather tool causes the cluster Proxy object to be collected without redaction, bypassing the sanitization provided by oc inspect. Proxy basic-auth credentials are exposed in the resulting archive, which may be shared with support teams or stored externally. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-532. Red Hat…

    Affected products in this advisory
    • Red Hat Advanced Cluster Management for Kubernetes 2.11
    • Red Hat Advanced Cluster Management for Kubernetes 2.13
    • Red Hat Advanced Cluster Management for Kubernetes 2.14
    • Red Hat Advanced Cluster Management for Kubernetes 2.15

    2 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • rhacm2/acm-must-gather-rhel9:1787263322
    • rhacm2/acm-must-gather-rhel9:1787260453
    • rhacm2/acm-must-gather-rhel9:1787189811
    • rhacm2/acm-must-gather-rhel9:1787238730

    8 more entries in the full advisory.

    Mitigation guidance
    • To mitigate the risk of credential exposure, restrict access to must-gather archives to authorized personnel only. Before sharing must-gather archives, especially with external entities, manually inspect and redact any sensitive information, including proxy basic-auth credentials, from the `cluster Proxy object` within the archive.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery