CVE-2026-41050Disclosure

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 21 mentions across 10 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 14 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 8d ago at 6 mentions (2026-05-08); latest day: 1
  • 21 total mentions across 10 days

Deep dive

Activity timeline21 mentions / 10d
02356Mentions · 2026-05-07: 3Mentions · 2026-05-08: 6Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 3Mentions · 2026-05-14: 3Mentions · 2026-05-22: 1Mentions · 2026-06-07: 1Mentions · 2026-07-01: 1PoC Mentioned / Linked · 2026-05-08: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 2Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 4Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 3Technical Details · 2026-05-22: 105-0705-0805-0905-1005-1105-1305-1405-2206-0707-01
Signal classification4 categories
Disclosure
1047.6%
Patch
733.3%
General
314.3%
PoC
14.8%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure1General1Patch1
2026-05-086
Disclosure3Patch2PoC1
2026-05-091
Disclosure1
2026-05-101
Disclosure1
2026-05-111
Patch1
2026-05-133
Disclosure2Patch1
2026-05-143
Disclosure1Patch2
2026-05-221
Disclosure1
2026-06-071
General1
2026-07-011
General1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    Rancher Fleet fixes a 9.9 CVSS flaw (CVE-2026-41050) allowing tenants to bypass ServiceAccount isolation and steal secrets. Upgrade your GitOps engine now! #Rancher #Kubernetes #GitOps #CyberSecurity #InfoSec #K8s #FleetSecurity #CVE #CloudNative #DevOps https://securityonline.info/rancher-fleet-critical-service-account-bypass-cve-2026-41050/ https://t.co/1BO8O1mWCy

    Post summary

    The tweet announces that Rancher Fleet has released a patch for CVE‑2026‑41050, a high‑severity ServiceAccount isolation bypass that could allow tenants to steal secrets, and urges users to upgrade immediately.

    050131841
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Rancher Fleetに重大(Critical)な脆弱性。CVE-2026-41050はCVSSスコア9.9で、アクセス限定されたテナントが隔離を突破しクラスタ管理者権限を取得可能。Helm deployerによるServiceAccountの偽装(impersonation)の適用不備。修正版提供あり。 https://securityonline.info/rancher-fleet-critical-service-account-bypass-cve-2026-41050/

    Post summary

    Rancher Fleet CVE-2026-41050 is a critical vulnerability (CVSS 9.9) that allows isolated tenants to break isolation and gain cluster admin rights via Helm deployer impersonation; a patch has already been released.

    00083993
    7.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnost v Rancher Fleet, CVE-2026-41050. Byla odhalena závažná zranitelnost typu eskalace oprávnění v platformě Rancher Fleet (GitOps nástroj pro správu Kubernetes), která umožňuje útočníkovi s omezeným přístupem k repozitáři obejít mechanismy multi-tenant izolace a získat efektivní oprávnění cluster-admin v navázaných Kubernetes clusterech. Zranitelnost je způsobena nesprávným zpracováním impersonace a umožňuje neoprávněný přístup ke Kubernetes Secrets, krádež přihlašovacích údajů, laterální pohyb v infrastruktuře a potenciálně úplné kompromitování prostředí. Ke zneužití dochází v případě, že útočník disponuje alespoň omezeným přístupem k repozitáři spravovanému pomocí Fleet v prostředí se sdílenými clustery nebo více tenanty. Oprava je dostupná v verzích Rancher v2.14.1, v2.13.5, v2.12.9 a v2.11.13; v případě Rancher v2.10.11 je nutné provést manuální aktualizaci. 📌Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    CVE-2026-41050 is a privilege‑escalation flaw in Rancher Fleet that lets attackers with limited repository access obtain cluster‑admin rights through improper impersonation. Patches are available for several Rancher releases, and users are urged to update immediately.

    02030590
    4.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting SUSE Rancher (CVE-2026-41050) https://vuldb.com/vuln/363505

    Post summary

    A new CVE (CVE-2026-41050) affecting SUSE Rancher has been added to the VulDB database, but the post contains no technical details, PoC, patch, or exploitation evidence.

    01030125
    2.3K followersView on X
  • 洛寒兮@LuochancyOWO
    PoC

    漏洞慢报: CVSS 9.9 — Rancher Fleet (CVE-2026-41050) · 5月8日 Service Account 绕过 → 攻击者可直接获取集群cluster-admin完整权限。K8s 集群一键沦陷。 CVSS 9.5 — Linux Kernel Dirty Frag (暂无CVE号) · 5月8日 PoC 已公开,严重本地用户提权漏洞。暂无漏洞补丁。

    Post summary

    The post reports a high‑severity CVE-2026-41050 in Rancher Fleet that allows cluster‑admin privilege escalation via a Service Account bypass, and announces a public PoC for a Linux kernel privilege‑escalation flaw, with no patch or known active exploitation at this time.

    10020292
    933 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Rancher Fleet Helm Impersonation Bypass (CVE-2026-41050) A critical vulnerability in Rancher Fleet's Helm deployer fails to properly apply ServiceAccount impersonation, allowing tenants to retain cluster-admin privileges during template rendering. This flaw enables attackers with git push access to read secrets from any namespace or bypass multi-tenant boundaries across downstream clusters. 👉 Affected: Fleet 0.15.0, 0.14.x ,0.13.x ,0.12.x ,0.11.x | Upgrade to 0.15.1, 0.14.5, 0.13.10, 0.12.14, 0.11.13

    Post summary

    CVE-2026-41050 is a critical Rancher Fleet Helm handler flaw that permits tenants to keep cluster‑admin authority during template rendering; upgrading to the listed patched releases mitigates the risk.

    0002070
    150 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. The Multitenant Isolation Collapse: Rancher Fleet CVE-2026-41050 Turns Helm Into a Secret Harvester

    Post summary

    The text announces a new Rancher Fleet CVE‐2026‑41050 that reportedly lets Helm harvest secrets, but offers no proof of concept, exploit code, patch information, or evidence of active exploitation.

    1000019
    253 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    5 Critical CVEs to Fix Now - vm2 sandbox Affected: vm2; Fleet Helm deployer; ERPNext Internet-facing risks dominate, led by sandbox escapes in Node.js vm2 and exposure through automation tooling. • CVE-2026-43997 (CVSS 10.0) iControl REST vulnerability allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that allow running arbitrary commands. Affected versions: unspecified. • CVE-2026-44005 (CVSS 10.0) vm2's bridge exposes mutable proxies for host-realm intrinsic prototypes and forwards sandbox writes into the underlying host objects, enabling host compromise; fixed in 3.11.0. Affected versions: 3.9.6-3.10.5. • CVE-2026-44006 (CVSS 10.0) vm2 prior to 3.11.0 allows reaching BaseHandler.getPrototypeOf to obtain arbitrary prototypes, enabling host access and command execution. Affected versions: <3.11.0. • CVE-2026-41050 (CVSS 9.9) Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to read secrets from any namespace on every downstream cluster targeted by their GitRepo. Affected versions: unspecified. • CVE-2026-44442 (CVSS 9.9) ERPNext before 16.9.1 fails to enforce proper authorization checks, allowing data modification beyond the holder’s permitted role. Affected versions: before 16.9.1. 🛠️ Action • Patch vm2 to the fixed 3.11.x series (≥3.11.0, ideally 3.11.2+); upgrade ERPNext to 16.9.1 or later; apply vendor advisories for Fleet Helm deployer. • Prioritize internet-facing instances and edge appliances for remediation first. • If a fix is not available yet, apply mitigations: restrict exposure, disable risky features, rotate credentials where applicable. • Add detections for exploitation patterns: sandbox escapes, host-prototype mutations, unauthorized API/config changes, and unusual process spawns. • Hunt for indicators in logs, EDR, WAF related to the affected services during the disclosure window. • Validate remediation with version checks and configuration verification, and monitor for reversion or new indicators.

    Post summary

    The advisory highlights five critical CVEs, provides detailed technical information, and emphasizes immediate patching and mitigation for affected systems.

    0001050
    545 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Rancher Fleet の深刻な脆弱性 CVE-2026-41050 が FIX:Cluster-Admin 権限への昇格 https://iototsecnews.jp/2026/05/08/critical-vulnerability-in-rancher-fleet-enables-full-cluster-admin-privileges/ 大規模な Kubernetes クラスタを管理するツール Rancher Fleet に見つかった、きわめて深刻な脆弱性について解説する記事です。問題の原因は、プログラムを配備する Helm デプロイヤーという機能において、本来は制限されたユーザー権限で動くべき処理が、誤ってシステム最高権限 (cluster-admin) で実行されてしまう不備にあります。Git リポジトリにアクセスできるユーザーが、この隙を突くと、特定の関数 (lookup) や設定ファイルの悪用が可能となり、他のユーザーやシステム全体の重要なパスワード (Secret) の窃取へといたります。ご利用のチームは、ご注意ください。 #CVE202641050 #Fleet #Kubernetes #Rancher #Vulnerability

    Post summary

    The article discloses a critical privilege‑escalation flaw in Rancher Fleet’s Helm deployer, detailing how users with Git repository access can leverage lookup functions to extract cluster secrets.

    01000122
    491 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Rancher Fleet, Multi-Tenant Isolation Bypass, #CVE-2026-41050 (Critical) -DC-Jul2026-802 https://dailycve.com/rancher-fleet-multi-tenant-isolation-bypass-cve-2026-41050-critical-dc-jul2026-802/

    Post summary

    The post announces a new critical vulnerability (CVE-2026-41050) affecting Rancher Fleet’s Multi‑Tenant Isolation but offers no further technical, exploit, or mitigation details.

    0000046
    217 followersView on X
  • nivelepsilon@FpeSre
    Disclosure

    Rancher Fleet CVE-2026-41050 lets any tenant with git push access harvest cluster-admin tokens via a Helm chart. GitOps is supposed to deploy apps, not hand out the keys to the kingdom. Multi-tenant isolation was more of a suggestion. ⛵ #Kubernetes https://gbhackers.com/critical-vulnerability-in-rancher-fleet/

    Post summary

    The tweet highlights a newly disclosed Rancher Fleet vulnerability (CVE-2026-41050) that enables tenants with git push privileges to retrieve cluster‑admin tokens through a Helm chart, exposing a multi‑tenant isolation flaw.

    0000033
    46 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Patch

    Today: 0 new KEV adds, 16 critical CVEs. The 3 to know: - vm2: 8 new criticals — 3.10.5 isn't safe, ship 3.11.3. - fast-jwt &lt;6.2.4: async key-resolver bypass skips JWT validation. - Rancher Fleet CVE-2026-41050: tenant reads cluster-wide secrets. https://github.com/patriksimek/vm2/security/advisories

    Post summary

    The tweet reports three critical CVEs, highlights the need to update vm2 to 3.11.3, outlines bypasses in fast‑jwt and a privilege escalation flaw in Rancher Fleet, and points readers to a GitHub advisory for further details.

    0000040
    35 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41050 Unauthorized Secret Access via ServiceAccount Impersonation in Fl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41050 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-41050, describing unauthorized secret access via ServiceAccount impersonation and provides a link to a vulnerability database for more details.

    0000053
    4.0K followersView on X
  • MikeinMalaga@MikeinMalaga
    Patch

    ⚠️ Rancher Fleet CVE-2026-41050: bypass de Helm impersonation. Un tenant con git push escala a cluster-admin y rompe multi-tenant en K8s 🔓 Patch: Fleet 0.15.1/0.14.5/0.13.10/0.12.14/0.11.13 🛠️ https://gbhackers.com/critical-vulnerability-in-rancher-fleet/ #DevOps #Kubernetes #GitOps #DevSecOps #CloudSecurity

    Post summary

    The post highlights CVE‑2026‑41050 in Rancher Fleet, explaining how a tenant can gain cluster‑admin rights via a git push, and lists specific Fleet versions that contain the fix.

    0000034
    59 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-41050: Rancher Fleet Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-41050-rancher-fleet-kubernetes-secrets-exposure/ hashtag#CVE202641050 hashtag#Cyberflaws hashtag#Cybersecurity

    Post summary

    The article announces CVE‑2026‑41050, a Rancher Fleet vulnerability that can expose Kubernetes secrets, but it provides no evidence of PoC, exploitation, or patch information.

    0000035
    9 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-41050: Rancher Fleet Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-41050-rancher-fleet-kubernetes-secrets-exposure/ hashtag#CVE202641050 hashtag#Cyberflaws hashtag#Cybersecurity

    Post summary

    The tweet links to a disclosure article announcing that CVE‑2026‑41050 in Rancher Fleet could expose Kubernetes secrets, but it does not provide PoC code, exploit details, or a patch.

    0000028
    2 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-41050: Rancher Fleet Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-41050-rancher-fleet-kubernetes-secrets-exposure/ hashtag#CVE202641050 hashtag#Cyberflaws hashtag#Cybersecurity

    Post summary

    The tweet announces CVE‑2026‑41050 affecting Rancher Fleet, indicating it exposes Kubernetes secrets, but provides no evidence of exploitation, PoC, patch, or technical details.

    0000042
    5 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🛡️ A critical Rancher Fleet flaw (CVE-2026-41050) can let Kubernetes tenants gain full cluster-admin access and steal secrets across downstream clusters. Shared DevOps environments are especially at risk. Patch immediately. https://thecyberedition.com/critical-rancher-fleet-bug/ #Kubernetes #CyberSecurity

    Post summary

    The post discloses a critical Rancher Fleet vulnerability that allows tenants to acquire cluster‑admin rights and exfiltrate secrets, with no PoC or active exploitation evidence, but urges immediate patching.

    0000045
    727 followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [CRITICAL] - A critical severity vulnerability (CVSS 9.9) has been identified in SUSE Rancher Fleet, the GitOps continuous delivery engine used for managing Kubernetes clusters at scale. The flaw, tracked as CVE-2026-41050, allows... https://www.enigma-global.com/og/report/critical-9-9-cvss-vulnerability-in-suse-rancher-fleet-cve-2026-41050-enables-mowsuca6-l5pw

    Post summary

    Intel Report announces a critical vulnerability (CVE‑2026‑41050) in SUSE Rancher Fleet with a CVSS score of 9.9, but provides neither proof of concept, exploit code, active exploitation evidence, nor patch information.

    0000033
    8 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    General

    Today (Thu, May 7): 1 KEV add, 12 critical CVEs. Ivanti EPMM admin RCE went out earlier. Long tail: - Gotenberg unauth RCE (CVE-2026-42589, 9.8) - intercom-client/intercom-php — compromised npm + Composer packages - Rancher Fleet Helm bypass (CVE-2026-41050, 9.9)

    Post summary

    The post enumerates several recent critical CVEs with their severity scores and notes a prior Ivanti EPMM admin RCE, but offers no detail on active exploitation, PoC, exploitation tools, or remediation.

    0000059
    34 followersView on X

Explore more