CVE-2026-41050
CRITICALHelm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
Title source: cnaDescription
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
References (2)
Core 2
Scores
CVSS v3
9.9
EPSS
0.0002
EPSS Percentile
4.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-863
Status
published
Products (10)
rancher/fleet
0.11.0 - 0.11.13Go
rancher/fleet
0.12.0 - 0.12.14Go
rancher/fleet
0.13.0 - 0.13.10Go
rancher/fleet
0.14.0 - 0.14.5Go
rancher/fleet
0.15.0 - 0.15.1Go
SUSE/Rancher
0.11.0 - 0.11.13
SUSE/Rancher
0.12.0 - 0.12.14
SUSE/Rancher
0.13.0 - 0.13.10
SUSE/Rancher
0.14.0 - 0.14.5
SUSE/Rancher
0.15.0 - 0.15.1
Published
May 13, 2026
Tracked Since
May 13, 2026