LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-44935

suse · rancher fleet

Published
CVSS9.9
Severitycritical
WeaknessCWE-1287
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44935

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44935.