CVE-2026-44935
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer in github.com/rancher/fleet
Beschreibung
Fehlende Validierung von "valuesFrom"-Verweisen im Helm-Deployer von SUSE Rancher Fleet in Versionen vor 0.15.2, 0.14 vor 0.14.6, 0.13 vor 0.13.11 und 0.12 vor 0.12.15 könnte von Eigentümern eines Tenants genutzt werden, um auf die Fleet-Anmeldeinformationen anderer Tenant zu zugreifen.
Metriken
Weakness-Klassen (CWE)
CWE-1287Base
Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-07-06 12:44 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.12.0 up to (excluding) 0.12.15 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.13.0 up to (excluding) 0.13.11 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.14.0 up to (excluding) 0.14.6 *cpe:2.3:a:suse:rancher_fleet:*:*:*:*:*:*:*:* versions from (including) 0.15.0 up to (excluding) 0.15.2
- Reference Type: SUSE: https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x Types: Vendor Advisory
- CVE Modified2026-07-03 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-07-02 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-44935","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-02 17:16 UTC· meissner@suse.de
- Affected: Rancher
- Description: Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-1287
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
go
github.com/rancher/fleet0.12.0
go
github.com/rancher/fleet0.13.0
go
github.com/rancher/fleet0.14.0
go
github.com/rancher/fleet0.15.0