Critical Vulnerability in Rancher Fleet Enables Full Cluster-Admin Privileges
ID: 4d6cf031-fe84-5fd9-81e8-50bb12c90816
STIX ID: report--4d6cf031-fe84-5fd9-81e8-50bb12c90816
Feed Name: GBHackers
SUSE Rancher Fleet is affected by a critical vulnerability (CVE-2026-41050) that lets attackers with push access deploy Helm charts or Fleet configuration that abuse the Helm lookup function and valuesFrom to read secrets using fleet-agent cluster-admin credentials, enabling secret exfiltration and full cluster-admin escalation; the report lists affected Fleet and Rancher versions and advises immediate patching and mitigations (disable untrusted repos, audit repositories for lookup usage, rotate exposed secrets, and enable API audit logging).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
