在 Rancher Manager 中发现了一个漏洞,其中 Fleet Agent 使用自身的 cluster-admin 凭证(而非部署中绑定的 ServiceAccount)将资源写入下游集群。该问题影响了多租户环境,在这些环境中,不同的租户共享相同的下游集群,例如同一组织内的不同特权团队或非信任团队。这可能导致配置文件被覆盖。 此问题影响了 SUSE Rancher Fleet 版本在 0.16 之前的 0.16.x(具体为 0.16.2 之前)、0.15.x(0.15.7 之前)以及 0.14.x(0.14
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88804 | 9.6 CRITICAL | Unauthenticated update of public UI settings leading to stored cross-site scripting in Ran |
| CVE-2026-78424 | 8.8 HIGH | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o |
| CVE-2026-88805 | 8.1 HIGH | Session Not Revoked Server-Side on Logout in Rancher |
| CVE-2026-93538 | 7.1 HIGH | Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen |
| CVE-2026-93540 | 6.5 MEDIUM | Fleet applies namespace labels and annotations without the bundle's service account privil |
| CVE-2026-93537 | 6.5 MEDIUM | Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir |
| CVE-2026-93539 | 5.4 MEDIUM | Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver |
No comments yet