SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75036

MEDIUM · CVSS 5.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Fleet's Helm template preprocessing allows users to supply bundle content that can lead to the disclosure of cluster metadata and information about network resources accessible from the Fleet controller. This issue primarily affects versions of Fleet prior to 0.12.19, 0.13.15, 0.14.10, 0.15.6, and 0.16.1. Organizations using affected Fleet versions should prioritize remediation to prevent potential information leaks, especially in environments with restricted outbound traffic.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75036
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource can cause the Fleet controller to: - Disclose cluster metadata available to the templating context. - Reveal information about hosts reachable from the controller's network position. Because the disclosure channel is name resolution, it may remain effective in environments where outbound traffic is otherwise restricted. The disclosed information is limited to values exposed to the Fleet templating context and to name resolution results. Integrity and availability of managed clusters are not affected. This issue affects Fleet: from 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.