Executive brief
SUSE Rancher Fleet, a tool used to manage and deploy applications across large groups of Kubernetes clusters, contains a vulnerability that affects multi-tenant environments. In these setups, one user or team could bypass security boundaries to access sensitive credentials, secrets, and configuration data belonging to other teams. This could allow an attacker to take full control over shared clusters or steal sensitive information used by other parts of the organization.
Technical details
A vulnerability in the Helm Deployer component of SUSE Rancher Fleet arises from improper validation of 'valuesFrom' references. In multi-tenant environments where different tenants share downstream clusters, an attacker with low-privileged access can use 'valuesFrom' in a fleet.yaml file (via GitRepo) or a HelmOp resource to read secrets and ConfigMaps across all namespaces, provided the resource names are known or guessed. Additionally, attackers can deploy HelmOp and Bundle resources without being restricted to a specific service account, potentially escalating privileges to cluster-wide resources. The fix introduces a new Policy resource to enforce specific service accounts and restrict repository URLs.
Affected products
- SUSE Rancher Fleet 0.15.0 before 0.15.2, 0.14.0 before 0.14.6, 0.13.0 before 0.13.11, 0.12.0 before 0.12.15
Timeline
- 2026-05-27: advisory: GitHub advisory published by Rancher team
- 2026-07-02: disclosed: NVD publication date