CVE-2026-55998: Suse Rancher

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle.

Affected products

  • Suse Rancher: from 2.14.0, before 2.14.4 (fixed in 2.14.4); from 2.13.0, before 2.13.8 (fixed in 2.13.8); from 2.12.0, before 2.12.12 (fixed in 2.12.12); from 2.11.0, before 2.11.16 (fixed in 2.11.16)

Published 2026-08-05. Last modified 2026-09-01.