CVE-2026-44938 Details
Description
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.
A vulnerability exists in Fleet's agent-side deployer, specifically in versions 0.15.0 prior to 0.15.2, 0.14.0 prior to 0.14.6, 0.13.0 prior to 0.13.11, and 0.12.0 prior to 0.12.15. The issue arises because the deployer failed to properly filter security-sensitive keys from 'namespaceLabels' in 'fleet.yaml' or 'BundleDeployment.spec.options.namespaceLabels' when applying them to the target namespace. This oversight allows an attacker with git push access to a Fleet-monitored repository to overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. As a result, the attacker can weaken admission controls and deploy workloads that PSS policies would typically block.
Users are advised to upgrade to Fleet versions 0.15.2, 0.14.6, 0.13.11, or 0.12.15, all of which include the necessary patch. If an immediate upgrade is not possible, consider deploying NeuVector as a primary workaround, which can block privileged containers even if PSS labels are downgraded. Alternatively, restrict repository access in multi-tenant setups to reduce the attack surface.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44938 | [email protected] | |
| https://github.com/advisories/GHSA-864g-863m-vcvq | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |