CVE-2026-44935
9.9
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.1 / Impact: 6.0
Source: meissner@suse.de (Secondary)
Description
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
Affected (4)
Products: Suse: Rancher Fleet
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 0.12.0 to 0.12.15 |
References (1)
Source: meissner@suse.de
Vendor Advisory
Timeline
No history available yet.