← Back

CVE-2026-44935

nvd nist
Published: Jul 2, 2026Modified: Jul 6, 2026

JSON object

Loading...
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: meissner@suse.de (Secondary)

Description

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

Affected (4)

Products: Suse: Rancher Fleet
1 product
Rancher Fleet
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Suse
From 0.12.0 to 0.12.15
From 0.13.0 to 0.13.11
From 0.14.0 to 0.14.6
From 0.15.0 to 0.15.2

References (1)

Timeline

No history available yet.