Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
0.15.0 (semver) before 0.15.1
affected
0.14.0 (semver) before 0.14.5
affected
0.13.0 (semver) before 0.13.10
affected
0.12.0 (semver) before 0.12.14
affected
0.11.0 (semver) before 0.11.13
affected
Description
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
Problem types
CWE-863: Incorrect Authorization
Product status
0.15.0 (semver) before 0.15.1
0.14.0 (semver) before 0.14.5
0.13.0 (semver) before 0.13.10
0.12.0 (semver) before 0.12.14
0.11.0 (semver) before 0.11.13
Credits
https://github.com/kodareef5
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41050
github.com/advisories/GHSA-765j-qfrp-hm3j