CVE-2026-88808High· 8.8▾ TwilightA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tena…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.
This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93538High· 7.1A cross-tenant authorization issue was discovered in SUSE Rancher Fleet
CVE-2026-93539Medium· 5.4A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service)
CVE-2026-93540Medium· 6.5A privilege mismatch was found in Fleet
CVE-2026-93537Medium· 6.5A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesyst…
CVE-2026-101047Medium· 5.3Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token
CVE-2026-101045High· 8.0Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata