CVE-2026-41050

CRITICAL

Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering

Title source: cna
STIX 2.1

Description

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

Scores

CVSS v3 9.9
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (10)
rancher/fleet 0.11.0 - 0.11.13Go
rancher/fleet 0.12.0 - 0.12.14Go
rancher/fleet 0.13.0 - 0.13.10Go
rancher/fleet 0.14.0 - 0.14.5Go
rancher/fleet 0.15.0 - 0.15.1Go
SUSE/Rancher 0.11.0 - 0.11.13
SUSE/Rancher 0.12.0 - 0.12.14
SUSE/Rancher 0.13.0 - 0.13.10
SUSE/Rancher 0.14.0 - 0.14.5
SUSE/Rancher 0.15.0 - 0.15.1
Published May 13, 2026
Tracked Since May 13, 2026