← Back to CVE search

CVE-2026-44935

SUSE Rancher Fleet

Description

Missing validation of -valuesFrom- references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

CVSS 9.9EPSS 0.41200000000000003%Risk 1.03
View source
Published
2026-07-02 17:16:59
Affected versions
<0.15.2, <0.14.6, <0.13.11, <0.12.15
Type
Critical software
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H