---
id: CVE-2026-93539
title: Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
summary: >-
  A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob
  webhook service). When a webhook secret is not configured, incoming webhook
  requests are accepted without verification, and processing a request can
  change the sp…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cvssSource: cna
cwe:
  - CWE-306
vendor: SUSE
product: Fleet
affected:
  - Fleet >= 0.16.0 < 0.16.2
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T14:19:55.071Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-93539'
references:
  - url: 'https://github.com/rancher/fleet/security/advisories/GHSA-8vfv-33cg-g75q'
tags:
  - cve.org
ingestedAt: '2026-09-28T15:13:31.605Z'
---

## Overview

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside

the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.

## Affected

- `Fleet >= 0.16.0 < 0.16.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
