CVE-2026-44935

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet

criticalEPSS 0.5 %

Beschreibung

Fehlende Validierung von "valuesFrom"-Verweisen im Helm-Deployer von SUSE Rancher Fleet in Versionen vor 0.15.2, 0.14 vor 0.14.6, 0.13 vor 0.13.11 und 0.12 vor 0.12.15 könnte von Eigentümern eines Tenants genutzt werden, um auf die Fleet-Anmeldeinformationen anderer Tenant zu zugreifen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.9
Quelle: nvd-v3
40.6 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-07 15:26 UTC
CWE-1287

Weakness-Klassen (CWE)

  • CWE-1287Base

    Improper Validation of Specified Type of Input

    The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-06 12:44 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.12.0 up to (excluding) 0.12.15 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.13.0 up to (excluding) 0.13.11 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.14.0 up to (excluding) 0.14.6 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.15.0 up to (excluding) 0.15.2
    • Reference Type: SUSE: https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x Types: Vendor Advisory
  2. CVE Modified2026-07-03 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. CVE Modified2026-07-02 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  4. New CVE Received2026-07-02 17:16 UTC· meissner@suse.de
    • Affected: Rancher
    • Description: Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-1287

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • go

    github.com/rancher/fleet0.12.0

  • go

    github.com/rancher/fleet0.13.0

  • go

    github.com/rancher/fleet0.14.0

  • go

    github.com/rancher/fleet0.15.0

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-44935