CVE-2026-44939: Suse Rancher
Critical severity, CVSS 9.4. EPSS: 1.3% chance of exploitation in the next 30 days.
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
Affected products
- Suse Rancher: from 2.14.0, before 2.14.2 (fixed in 2.14.2); from 2.13.0, before 2.13.6 (fixed in 2.13.6); from 2.12.0, before 2.12.10 (fixed in 2.12.10); from 2.11.0, before 2.11.14 (fixed in 2.11.14); from 2.10.0, before 2.10.12 (fixed in 2.10.12)
Published 2026-06-19. Last modified 2026-06-24.