{"id":"CVE-2026-41050","aliases":["GO-2026-5207"],"url":"https://o3.security/vulnerability/CVE-2026-41050","summary":"Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering","details":"### Impact\n\nFleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.\n\n**Helm `lookup` bypass:** The Helm template engine ran Kubernetes API queries with the fleet-agent's cluster-admin credentials instead of the impersonated ServiceAccount. A chart template could therefore access resources beyond the tenant's RBAC scope.\n\n**`valuesFrom` bypass:** Secret and ConfigMap references in `fleet.yaml` `helm.valuesFrom` were read using the fleet-agent's cluster-admin client. A tenant could reference resources in namespaces the impersonated ServiceAccount has no access to.\nBoth issues break Fleet's multi-tenant impersonation boundary. The leaked credentials may belong to external services, making the full impact non-deterministic.\nSingle-tenant deployments where all users are trusted are not affected.\n\n**Important:**\n- For the exposure of additional credentials, the final impact severity for confidentiality, integrity and availability is dependent on the permissions the leaked credentials have on their services.\n- It is recommended to review for potentially leaked credentials in this scenario and to change them if deemed necessary.\n\nPlease consult the associated  [MITRE ATT&CK - Technique - Account Access Removal](https://attack.mitre.org/techniques/T1531/) for further information about this category of attack.\n\n### Patches\n\nBoth issues are fixed by ensuring the Helm action configuration consistently uses the impersonated ServiceAccount credentials throughout all Helm operations.\n\nPatched versions of Rancher include releases `v2.14.1`, `v2.13.5`, `v2.12.9`, and `v2.11.13`. For Rancher `v2.10.11`, users must manually update their Fleet deployment to version`v0.11.13`.\n\n### Workarounds\n\nNo workaround fully mitigates the issue for multi-tenant deployments. The patches should be applied as soon as they are available.\n\nThe following measures reduce the attack surface but do not close either vulnerability:\n\n- Restrict git push access to Fleet-monitored repositories to trusted users only. In a multi-tenant setup this removes the precondition entirely, but is often not operationally viable.\n- Use `GitRepoRestriction` resources to limit which ServiceAccounts each namespace is allowed to use, restricting the set of users who can configure impersonation at all.\n- Audit deployed chart templates for `lookup` calls and `fleet.yaml` files for cross-namespace `valuesFrom` references as a detective control.\n\n### Resources\n\nIf there are any questions or comments about this advisory:\n\n- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquiries.\n- Open an issue in the [Rancher](https://github.com/rancher/rancher/issues/new/choose) repository.\n- Verify using the [support matrix](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/) and [product support lifecycle](https://www.suse.com/lifecycle/).","published":"2026-05-07T01:26:06Z","modified":"2026-06-25T19:56:22.698371981Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.0039,"percentile":0.32076,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/rancher/fleet","fixedVersion":"0.15.1"},{"ecosystem":"Go","name":"github.com/rancher/fleet","fixedVersion":"0.14.5"},{"ecosystem":"Go","name":"github.com/rancher/fleet","fixedVersion":"0.13.10"},{"ecosystem":"Go","name":"github.com/rancher/fleet","fixedVersion":"0.12.14"},{"ecosystem":"Go","name":"github.com/rancher/fleet","fixedVersion":"0.11.13"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rancher/fleet/security/advisories/GHSA-765j-qfrp-hm3j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41050"},{"type":"WEB","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-41050"},{"type":"PACKAGE","url":"https://github.com/rancher/fleet"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T19:56:22.698371981Z"}}