Vulnerability Description
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41050
- https://github.com/advisories/GHSA-765j-qfrp-hm3j
FAQ
What is CVE-2026-41050?
CVE-2026-41050 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on e...
How severe is CVE-2026-41050?
CVE-2026-41050 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-41050?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.