---
id: CVE-2026-44940
title: >-
  The rancher-extension-stackstate extension in SUSE Observability exposes
  service tokens in plain configuration or insecure locations rather than
  managing them securely
summary: >-
  The rancher-extension-stackstate extension in SUSE Observability exposes
  service tokens in plain configuration or insecure locations rather than
  managing them securely. An attacker with minimal access could obtain the token
  to gain unaut…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-312
vendor: SUSE
product: rancher-extension-stackstate
affected:
  - rancher-extension-stackstate < 2.13.6
  - rancher-extension-stackstate >= 2.14.0 < 2.14.2
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:07:38.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44940'
references:
  - url: 'https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44940'
    label: meissner@suse.de
  - url: >-
      https://github.com/StackVista/rancher-extension-stackstate/security/advisories/GHSA-7c27-jc6w-pw95
    label: meissner@suse.de
tags:
  - nvd
  - cve.org
epss: 0.00134
epssPercentile: 0.03244
ingestedAt: '2026-09-17T07:13:35.793Z'
---

## Overview

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
