High severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-44938
Description
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace.
An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/fleetGo | >= 0.15.0, < 0.15.2 | 0.15.2 |
github.com/rancher/fleetGo | >= 0.14.0, < 0.14.6 | 0.14.6 |
github.com/rancher/fleetGo | >= 0.13.0, < 0.13.11 | 0.13.11 |
github.com/rancher/fleetGo | >= 0.12.0, < 0.12.15 | 0.12.15 |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.