CVE-2026-44938Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-01: 2Mentions · 2026-07-08: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-08: 107-0107-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-012
Disclosure2
2026-07-081
Disclosure1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-44938 (CVSS 8.8) Fleet agent-side deployer vulnerability allows attackers with git push access to overwrite Pod Security Standards labels, weakening admission controls. Impact: Unauthorized workload deployment #CVE #Vulnerability #PatchNow https://t.co/vwZR0WI3Ls

    Post summary

    The post discloses a high‑severity CVE-2026-44938, detailing how attackers with git push privileges can override Pod Security Standards labels to deploy unauthorized workloads, but it provides no PoC, exploit code or patch information.

    0000048
    68 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Fleet (Rancher) Webhook Authentication Bypass Vulnerability, #CVE-2026-44938 (High) -DC-Jul2026-800 https://dailycve.com/fleet-rancher-webhook-authentication-bypass-vulnerability-cve-2026-44938-high-dc-jul2026-800/

    Post summary

    A new CVE (CVE-2026-44938) affecting Fleet (Rancher) is announced as a webhook authentication bypass with high severity; no PoC, exploit, or patch information is provided.

    0000051
    217 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Rancher Fleet, PSS Bypass via Namespace Labels, #CVE-2026-44938 (High) -DC-Jul2026-801 https://dailycve.com/rancher-fleet-pss-bypass-via-namespace-labels-cve-2026-44938-high-dc-jul2026-801/

    Post summary

    The text announces the CVE-2026-44938 vulnerability in Rancher Fleet, noting a PSS bypass via namespace labels, but offers no further technical details, exploit references, or mitigation information.

    0000053
    217 followersView on X

Explore more