CVE-2026-44937: Suse Rancher Fleet
High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
Affected products
- Suse Rancher Fleet: from 0.12.0, before 0.12.15 (fixed in 0.12.15); from 0.13.0, before 0.13.11 (fixed in 0.13.11); from 0.14.0, before 0.14.6 (fixed in 0.14.6); from 0.15.0, before 0.15.2 (fixed in 0.15.2)
Published 2026-07-06. Last modified 2026-07-09.