CVE-2026-93539Medium· 5.4▾ SunlitA vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the sp…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside
the namespaces they are authorized for. This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.
Fleet >= 0.16.0 < 0.16.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-21952High· 7.5A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS
CVE-2026-93538High· 7.1Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet
CVE-2026-93540Medium· 6.5Fleet applies namespace labels and annotations without the bundle's service account privileges
CVE-2026-93537Medium· 6.5A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesyst…
CVE-2026-101047Medium· 5.3Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token
CVE-2026-101045High· 8.0Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata