CVE-2026-44935: Suse Rancher Fleet
Critical severity, CVSS 9.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
Affected products
- Suse Rancher Fleet: from 0.12.0, before 0.12.15 (fixed in 0.12.15); from 0.13.0, before 0.13.11 (fixed in 0.13.11); from 0.14.0, before 0.14.6 (fixed in 0.14.6); from 0.15.0, before 0.15.2 (fixed in 0.15.2)
Published 2026-07-02. Last modified 2026-07-06.