CVE-2026-41050
EUVD-2026-2991713.05.2026, 08:16
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| suse | rancher | 0.15.0 ≤ 𝑥 < 0.15.1 | CNA |
| suse | rancher | 0.14.0 ≤ 𝑥 < 0.14.5 | CNA |
| suse | rancher | 0.13.0 ≤ 𝑥 < 0.13.10 | CNA |
| suse | rancher | 0.12.0 ≤ 𝑥 < 0.12.14 | CNA |
| suse | rancher | 0.11.0 ≤ 𝑥 < 0.11.13 | CNA |