CVE-2026-41050
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git pus
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their GitRepo.
CRITICAL · CVSS 9.9
EPSS 0.00016
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0