CVE-2026-41050: Suse Rancher

Critical severity, CVSS 9.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

Affected products

  • Suse Rancher: from 0.15.0, before 0.15.1 (fixed in 0.15.1); from 0.14.0, before 0.14.5 (fixed in 0.14.5); from 0.13.0, before 0.13.10 (fixed in 0.13.10); from 0.12.0, before 0.12.14 (fixed in 0.12.14); from 0.11.0, before 0.11.13 (fixed in 0.11.13)

Published 2026-05-13. Last modified 2026-06-17.