VYPR
High severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

CVE-2026-44938

Description

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace.

An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/rancher/fleetGo
>= 0.15.0, < 0.15.20.15.2
github.com/rancher/fleetGo
>= 0.14.0, < 0.14.60.14.6
github.com/rancher/fleetGo
>= 0.13.0, < 0.13.110.13.11
github.com/rancher/fleetGo
>= 0.12.0, < 0.12.150.12.15

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.