Security Advisory

CVE-2026-41050

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 08:04:57
Last updated 2026-05-14 03:55:58
Assigner suse
CVSS score 9.9
State PUBLISHED

Description

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.