GPU VulnDB

Database/Container, Kubernetes & orchestration

Rancher Fleet: bundle content can read files from the bundle-processing job and leak Helm registry credentials

CVSS 6.5CVE-2026-93537Container, Kubernetes & orchestrationcurated

Impact

Anyone who can push to a Git repository referenced by a GitRepo, or who can create or modify a GitRepo, can make Fleet read files off the filesystem of the environment that processes the bundle and embed their contents in the generated Bundle resource. That leaks configuration and credential material the user has no Kubernetes RBAC permission to read, explicitly including per-path Helm registry credentials mounted into the bundle-processing job. In a fleet where Rancher drives GPU node pools and the GPU Operator, those registry credentials are a path to publishing or replacing the images that run on accelerators, so the confidentiality loss turns into a supply-chain foothold on the cluster.

Who can reach it

A user with Git push access to a repository Fleet watches, or with Kubernetes permission to create or modify GitRepo resources. Authentication is required, but only low privilege - not cluster-admin, and no access to the target namespaces.

What to do

Upgrade Fleet to 0.16.2, 0.15.7, 0.14.11, 0.13.16 or 0.12.20 depending on your branch, which means rolling the Fleet controller and gitjob workloads - a controller restart, no node drain or reboot. Older unsupported versions are potentially affected with no fix. Treat any Helm registry credentials that were mounted into bundle-processing jobs as exposed and rotate them, and tighten who can create or modify GitRepo resources.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.