ServiceAccount Impersonation Flaw in Fleet by SUSE

⚠️ CVE-Referenzen: CVE-2026-41050
Suse - Rancher - CRITICAL - CVE-2026-41050. A significant security flaw has been identified in Fleet's Helm deployer, where ServiceAccount impersonation was not consistently enforced in two specific code paths. This oversight enables authenticated tenants with git push access to a Fleet-monitored repository to potentially access secrets across all namespaces on any downstream Kubernetes cluster tracked by their `GitRepo`. This could lead to unauthorized reading of sensitive information, raising critical concerns regarding the security posture of deployments using Fleet.
Quelle: securityvulnerability.io