Beveiligingsadvies

CVE-2026-41050

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-13 08:04:57
Laatst bijgewerkt 2026-05-14 03:55:58
Toegewezen door suse
CVSS-score 9.9
Status PUBLISHED

Beschrijving

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.