Incorrect Authorization Affecting github.com/rancher/fleet/internal/cmd/controller/helmops/reconciler package, versions >=0.12.0-alpha.1 <0.12.15-rc.2>=0.13.0-alpha.1 <0.13.11-rc.1>=0.14.0-alpha.1 <0.14.6-rc.2>=0.15.0-alpha.1 <0.15.2-rc.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.49% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERFLEETINTERNALCMDCONTROLLERHELMOPSRECONCILER-17808291
  • published3 Jul 2026
  • disclosed1 Jul 2026
  • creditUnknown

Introduced: 1 Jul 2026

CVE-2026-44935  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/fleet/internal/cmd/controller/helmops/reconciler to version 0.12.15-rc.2, 0.13.11-rc.1, 0.14.6-rc.2, 0.15.2-rc.2 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in the valuesFrom process. An attacker can gain unauthorized access to secrets and config maps across namespaces by crafting resources such as HelmOp or Bundle with references to arbitrary secrets, provided they know or can guess the name, namespace, and key. This is only exploitable if multiple tenants share the same downstream cluster in a multi-tenant environment.

Workaround

This vulnerability can be mitigated by ensuring that tenants do not have shared access to the same downstream clusters.

CVSS Base Scores

version 4.0
version 3.1