CRITICAL🇵🇱 Wersja polska

CVE-2026-44935

CVSS 9.9v3.1pub. 2026-07-02upd. 2026-07-06

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

🤖 AI Analysis
How it works

The 'valuesFrom' mechanism in Helm Deployer allows pointing to external sources of configuration values. Due to insufficient validation of these references, a person authenticated as the owner of one tenant can construct a reference pointing to resources (Fleet credentials) belonging to another tenant. The vulnerability thus enables circumventing tenant isolation boundaries without requiring administrative privileges to the system.

Impact

An attacker who is an authenticated user of one tenant can gain unauthorized access to Fleet credentials of other tenants, leading to violations of confidentiality, integrity, and availability of resources in a multi-tenant environment.

Mitigation & patch

Update SUSE Rancher Fleet to version: 0.12.15 or later (0.12 branch), 0.13.11 or later (0.13 branch), 0.14.6 or later (0.14 branch), 0.15.2 or later (0.15 branch). Details available in the official vendor security advisory: https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x

Who is affected

SUSE Rancher Fleet in versions: 0.12 before 0.12.15, 0.13 before 0.13.11, 0.14 before 0.14.6, and 0.15 before 0.15.2.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • SUSE Rancher Fleet

    APP
    Suse
    0.12.0 – 0.12.15 (excl.)0.13.0 – 0.13.11 (excl.)0.14.0 – 0.14.6 (excl.)0.15.0 – 0.15.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-44937HIGH8.3PL ✓same product

SSRF/fałszowanie żądań webhook w SUSE Rancher Fleet — DoS i downgrade

CVE-2026-44936MEDIUM5.0same product

Brak filtrowania, gdy pole helmRepoURLRegex nie jest ustawione w zasobie GitRepo w czytelniku bundli SUSE Ranc...

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same vendor

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany

CVE-2016-4117CRITICAL9.8⚠ KEVPL ✓same vendor

Adobe Flash Player — RCE umożliwiający wykonanie dowolnego kodu