CVE-2026-88808 - Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
CVE ID :CVE-2026-88808 Published : Sept. 28, 2026, 3:36 p.m. | 39 minutes ago Description :A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to...