Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
References
Configurations
No configuration.
History
13 May 2026, 15:35
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 08:16
Updated : 2026-05-13 15:35
NVD link : CVE-2026-41050
Mitre link : CVE-2026-41050
CVE.ORG link : CVE-2026-41050
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
