Answer in brief
CVE-2026-44938 records a High severity (CVSS 8.8) vulnerability in Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent. The current sources do not mark it as known exploited. The current feed maps SUSE/Rancher (generic), github.com/rancher/fleet (go), github.com/rancher/fleet (go), github.com/rancher/fleet (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps SUSE/Rancher (generic), github.com/rancher/fleet (go), github.com/rancher/fleet (go), github.com/rancher/fleet (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| SUSE/Ranchergeneric | >=0.15.0 <0.15.2 || >=0.14.0 <0.14.6 || >=0.13.0 <0.13.11 || >=0.12.0 <0.12.15 | 0.15.2, 0.14.6, 0.13.11, 0.12.15 |
| github.com/rancher/fleetgo | >=0.15.0,<0.15.2 | 0.15.2 |
| github.com/rancher/fleetgo | >=0.14.0,<0.14.6 | 0.14.6 |
| github.com/rancher/fleetgo | >=0.13.0,<0.13.11 | 0.13.11 |
| github.com/rancher/fleetgo | >=0.12.0,<0.12.15 | 0.12.15 |
Published upstream
Jul 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 1, 2026
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would otherwise block.
Quoted source text, attributed separately from HOL analysis.