logo

Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access

ID: e854ebe1-5ab6-5a54-b2a2-b195194bffa9

STIX ID: report--e854ebe1-5ab6-5a54-b2a2-b195194bffa9

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

**Rancher Fleet critical vulnerability (CVE-2026-41050):** Fleet's Helm deployer failed to consistently apply ServiceAccount impersonation in two code paths (Helm template lookups and helm.valuesFrom), allowing tenants with git push access to read secrets from any namespace on downstream clusters and potentially escalate to cluster-admin. The issue is rated CVSS 9.9; SUSE published patches for multiple Rancher versions and warns that no workaround fully mitigates the risk in multi-tenant deployments, recommending immediate upgrades and restriction of git push access as interim measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.