A critical vulnerability has been identified in the Helm Deployer component of SUSE Rancher Fleet, affecting versions 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11, and 0.12 before 0.12.15. The vulnerability stems from missing validation of 'valuesFrom' references, which could allow an attacker with access to one tenant's environment to access credentials belonging to other tenants. This poses a significant risk to multi-tenant deployments, as it enables unauthorized access to sensitive information. The CVSS score of 9.9 indicates a critical severity level, emphasizing the urgency of mitigation. Organizations utilizing these affected versions of Rancher Fleet should apply the latest security patches immediately to prevent potential exploitation. It is recommended to review deployment configurations and ensure that all instances are updated to the secure versions. No workarounds are available, and users are advised to follow official patching guidelines provided by the vendor. This vulnerability highlights the importance of maintaining up-to-date software in multi-tenant environments to mitigate risks associated with improper input validation.