9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
Basic Information
ID
CVE-2026-41050
Source
suse
Published
May 13, 2026 at 08:04
Modified
May 13, 2026 at 08:05
Affected Product
Vendor
SUSE
Product
Rancher
Version
0.15.0
Affected Versions
SUSE Rancher 0.15.0
SUSE Rancher 0.14.0
SUSE Rancher 0.13.0
SUSE Rancher 0.12.0
SUSE Rancher 0.11.0
SUSE Rancher 0.14.0
SUSE Rancher 0.13.0
SUSE Rancher 0.12.0
SUSE Rancher 0.11.0