CVE-2026-44935
- EPSS 0.41%
- Veröffentlicht 02.07.2026 16:00:06
- Zuletzt bearbeitet 06.07.2026 12:44:21
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenant...
CVE-2026-44948
- EPSS 0.29%
- Veröffentlicht 30.06.2026 15:12:17
- Zuletzt bearbeitet 02.07.2026 17:45:44
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a de...
- EPSS 0.23%
- Veröffentlicht 30.06.2026 14:41:34
- Zuletzt bearbeitet 02.07.2026 17:45:44
A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to t...
CVE-2026-44947
- EPSS 0.23%
- Veröffentlicht 30.06.2026 14:21:01
- Zuletzt bearbeitet 02.07.2026 17:45:44
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator re...
CVE-2026-44946
- EPSS 0.32%
- Veröffentlicht 30.06.2026 12:14:54
- Zuletzt bearbeitet 02.07.2026 19:58:48
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14...
CVE-2026-41053
- EPSS 0.45%
- Veröffentlicht 30.06.2026 11:38:25
- Zuletzt bearbeitet 02.07.2026 19:57:44
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
CVE-2026-41052
- EPSS 0.41%
- Veröffentlicht 29.06.2026 16:16:39
- Zuletzt bearbeitet 02.07.2026 19:48:21
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVE-2026-44939
- EPSS 1.28%
- Veröffentlicht 19.06.2026 12:13:39
- Zuletzt bearbeitet 24.06.2026 05:17:28
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious ...
CVE-2026-41050
- EPSS 0.39%
- Veröffentlicht 13.05.2026 08:04:57
- Zuletzt bearbeitet 13.05.2026 15:35:35
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo...
CVE-2026-25705
- EPSS 0.37%
- Veröffentlicht 13.05.2026 08:00:46
- Zuletzt bearbeitet 13.05.2026 15:35:35
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` fie...