GPU VulnDB

Database/Container, Kubernetes & orchestration

Rancher Fleet: unauthenticated webhook requests can change GitRepo polling interval in any namespace

CVSS 5.4CVE-2026-93539Container, Kubernetes & orchestrationcurated

Impact

When no webhook secret is configured, Fleet's gitjob webhook receiver accepts incoming requests without verification, and handling one can rewrite spec.pollingInterval on a matching GitRepo in any namespace. A caller with nothing but network reach to the webhook service - no Kubernetes credentials at all - can therefore alter GitOps configuration outside any namespace they are authorized for. The direct effect is limited to how often Fleet reconciles, but on a GPU fleet that governs how fast a corrected manifest, a pinned driver version or a rolled-back GPU Operator chart actually lands; stretching the interval quietly delays remediation across clusters. This is a distinct flaw from CVE-2026-93537 and affects only the 0.16 branch.

Who can reach it

Anyone with network access to the gitjob webhook service in a deployment that has no webhook secret configured. No Kubernetes credentials and no authentication needed.

What to do

Upgrade Fleet to 0.16.2 - older branches are not affected - which means rolling the gitjob deployment, a controller restart with no node drain. Configure a webhook secret so incoming requests are verified, and keep the webhook service off any network broader than the systems that legitimately post to it. Check pollingInterval values on your GitRepo resources for unexpected changes.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.