cbcvebase.
CVE-2026-41050
published 2026-05-13

CVE-2026-41050: Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored…

PriorityP357critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.38%
30.1th percentile
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

Affected

10 ranges
VendorProductVersion rangeFixed in
github.comrancher_fleet>= 0.11.0 < 0.11.130.11.13
github.comrancher_fleet>= 0.12.0 < 0.12.140.12.14
github.comrancher_fleet>= 0.13.0 < 0.13.100.13.10
github.comrancher_fleet>= 0.14.0 < 0.14.50.14.5
github.comrancher_fleet>= 0.15.0 < 0.15.10.15.1
suserancher>= 0.11.0 < 0.11.130.11.13
suserancher>= 0.12.0 < 0.12.140.12.14
suserancher>= 0.13.0 < 0.13.100.13.10
suserancher>= 0.14.0 < 0.14.50.14.5
suserancher>= 0.15.0 < 0.15.10.15.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.