PT-2026-85064 · Fleet · Fleet

CVE-2026-75036

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Fleet versions 0.12.0 through 0.12.18 Fleet versions 0.13.0 through 0.13.14 Fleet versions 0.14.0 through 0.14.9 Fleet versions 0.15.0 through 0.15.5 Fleet versions 0.16.0
Description An issue exists in the Helm template preprocessing of the Fleet controller. A user capable of providing bundle content to a repository referenced by a GitRepo resource can force the controller to reach network resources outside the management cluster. This can lead to the disclosure of cluster metadata available to the templating context and the revelation of hosts reachable from the controller's network position. Since the disclosure occurs via name resolution, it may function even in environments with restricted outbound traffic. The impact is limited to information disclosure; the integrity and availability of managed clusters remain unaffected.
Recommendations Update to version 0.12.19 Update to version 0.13.15 Update to version 0.14.10 Update to version 0.15.6 Update to version 0.16.1

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75036
GHSA-X9M6-XCJR-HPJP

Affected Products

Fleet