CVE-2026-88804
- EPSS 0.54%
- Veröffentlicht 28.09.2026 15:58:34
- Zuletzt bearbeitet 29.09.2026 21:32:59
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and ...
CVE-2026-88805
- EPSS 0.25%
- Veröffentlicht 28.09.2026 15:50:34
- Zuletzt bearbeitet 29.09.2026 21:32:59
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
CVE-2026-88808
- EPSS 0.27%
- Veröffentlicht 28.09.2026 15:36:13
- Zuletzt bearbeitet 07.10.2026 17:00:32
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environme...
CVE-2026-93540
- EPSS 0.17%
- Veröffentlicht 28.09.2026 14:45:42
- Zuletzt bearbeitet 07.10.2026 17:03:05
A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the re...
CVE-2026-93539
- EPSS 0.23%
- Veröffentlicht 28.09.2026 14:19:55
- Zuletzt bearbeitet 07.10.2026 17:08:05
A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInt...
CVE-2026-93538
- EPSS 0.17%
- Veröffentlicht 28.09.2026 14:10:21
- Zuletzt bearbeitet 07.10.2026 17:13:37
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the clust...
CVE-2026-93537
- EPSS 0.3%
- Veröffentlicht 28.09.2026 13:29:10
- Zuletzt bearbeitet 07.10.2026 17:19:57
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the env...
CVE-2026-75035
- EPSS 0.2%
- Veröffentlicht 03.09.2026 15:07:11
- Zuletzt bearbeitet 18.09.2026 14:26:46
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user c...
CVE-2026-75034
- EPSS 0.2%
- Veröffentlicht 03.09.2026 15:01:16
- Zuletzt bearbeitet 18.09.2026 14:37:50
A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-avai...
CVE-2026-75033
- EPSS 0.21%
- Veröffentlicht 03.09.2026 14:57:34
- Zuletzt bearbeitet 18.09.2026 14:56:19
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to crea...