Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access
ID: e854ebe1-5ab6-5a54-b2a2-b195194bffa9
STIX ID: report--e854ebe1-5ab6-5a54-b2a2-b195194bffa9
Feed Name: securityonline.info
**Rancher Fleet critical vulnerability (CVE-2026-41050):** Fleet's Helm deployer failed to consistently apply ServiceAccount impersonation in two code paths (Helm template lookups and helm.valuesFrom), allowing tenants with git push access to read secrets from any namespace on downstream clusters and potentially escalate to cluster-admin. The issue is rated CVSS 9.9; SUSE published patches for multiple Rancher versions and warns that no workaround fully mitigates the risk in multi-tenant deployments, recommending immediate upgrades and restriction of git push access as interim measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
