CVE-2026-44948: Suse Rancher
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.
Affected products
- Suse Rancher: from 0.12.0, before 0.12.16 (fixed in 0.12.16); from 0.13.0, before 0.13.12 (fixed in 0.13.12); from 0.14.0, before 0.14.7 (fixed in 0.14.7); from 0.15.0, before 0.15.3 (fixed in 0.15.3)
Published 2026-06-30. Last modified 2026-07-02.