<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:58:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-332482</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-332482</link>
      <description>EUVD-2026-332482</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-332482</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44935</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44935</link>
      <description>&lt;p&gt;Missing validation of &amp;#34;valuesFrom&amp;#34; references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing validation of &amp;#34;valuesFrom&amp;#34; references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44935</guid>
    </item>
    <item>
      <title>GHSA-xr65-5cpm-g36x — Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xr65-5cpm-g36x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/fleet&lt;/p&gt;
&lt;p&gt;### Impact
A vulnerability in Fleet for Rancher Manager affects multi-tenancy environments where different tenants share the same downstream clusters (e.g., different privileged or untrusted teams inside the same organization).&lt;/p&gt;
&lt;p&gt;On unpatched versions, tenants could bypass restrictions to access any config map or secret across all namespaces on the downstream cluster. They can create cluster-wide resources using `HelmOp` or `Bundle` without authorization.
Specifically, an attacker can exploit this vulnerability in the following ways:
1. Use `valuesFrom` in `fleet.yaml`(through a `GitRepo` resource) or a `HelmOp resource to read the contents of any secret an on the downstream cluster, provided they know or can guess the name, namespace, and key.
2. Deploy `HelmOp` and `Bundle` resources without being restricted to a specific service account for the Fleet agent.&lt;/p&gt;
&lt;p&gt;If you use Fleet in a multi-tenant environment, it&amp;#39;s recommended that you:
- Review your cluster and Fleet deployments logs for indicators of unauthorized access across tenant namespaces.
- Rotate any service accounts and credentials that might have been exposed.&lt;/p&gt;
&lt;p&gt;Please consult the associated  [MITRE ATT&amp;amp;CK - Technique - Unsecured Credentials](https://attack.mitre.org/techniques/T1552/) for further information about this category of attack.&lt;/p&gt;
&lt;p&gt;### Patches
To resolve this vulnerability, upgrade to a patched version of Fleet.  The new Policy resource allows you to:
- Configure `GitRepos`, `HelmOps`, and `Bundles` to requ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/fleet&lt;/p&gt;
&lt;p&gt;### Impact
A vulnerability in Fleet for Rancher Manager affects multi-tenancy environments where different tenants share the same downstream clusters (e.g., different privileged or untrusted teams inside the same organization).&lt;/p&gt;
&lt;p&gt;On unpatched versions, tenants could bypass restrictions to access any config map or secret across all namespaces on the downstream cluster. They can create cluster-wide resources using `HelmOp` or `Bundle` without authorization.
Specifically, an attacker can exploit this vulnerability in the following ways:
1. Use `valuesFrom` in `fleet.yaml`(through a `GitRepo` resource) or a `HelmOp resource to read the contents of any secret an on the downstream cluster, provided they know or can guess the name, namespace, and key.
2. Deploy `HelmOp` and `Bundle` resources without being restricted to a specific service account for the Fleet agent.&lt;/p&gt;
&lt;p&gt;If you use Fleet in a multi-tenant environment, it&amp;#39;s recommended that you:
- Review your cluster and Fleet deployments logs for indicators of unauthorized access across tenant namespaces.
- Rotate any service accounts and credentials that might have been exposed.&lt;/p&gt;
&lt;p&gt;Please consult the associated  [MITRE ATT&amp;amp;CK - Technique - Unsecured Credentials](https://attack.mitre.org/techniques/T1552/) for further information about this category of attack.&lt;/p&gt;
&lt;p&gt;### Patches
To resolve this vulnerability, upgrade to a patched version of Fleet.  The new Policy resource allows you to:
- Configure `GitRepos`, `HelmOps`, and `Bundles` to requ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xr65-5cpm-g36x</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1715 — Fleet: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1715</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fleet ausnutzen, um Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitskonfigurationen zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fleet ausnutzen, um Sicherheitsmechanismen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitskonfigurationen zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1715</guid>
    </item>
  </channel>
</rss>
