Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93537— Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory

Quick assessment

Affected
SUSE Rancher
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

能够向 GitRepo 资源所引用的代码仓库提供 bundle 内容的用户(例如通过 Git push 访问权限,或通过创建或修改 GitRepo 的权限),可以诱导 SUSE Rancher Fleet 读取处理该 bundle 的环境的文件系统中的文件,并将其内容包含在生成的 Bundle 资源中。此行为可能暴露用户无权通过 Kubernetes RBAC 权限读取的配置信息或凭据材料,其中包括在配置基于路径的 Helm 凭据时提供给 bundle 处理任务的 Helm 注册表凭据。 此漏洞影响以下版本的 Fl

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93537

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
Source: CVE Program / CVE List V5
Vulnerability Description
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Rancher 0.16.0 ~ 0.16.2 -

II. Public POCs for CVE-2026-93537

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93537

请登录查看更多情报信息。

Other References for CVE-2026-93537 (1)

Same Patch Batch · SUSE · 2026-09-28 · 5 CVEs total

CVE-2026-78424 8.8 HIGH OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o
CVE-2026-93538 7.1 HIGH Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen
CVE-2026-93540 6.5 MEDIUM Fleet applies namespace labels and annotations without the bundle's service account privil
CVE-2026-93539 5.4 MEDIUM Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver

IV. Related Vulnerabilities

V. Comments for CVE-2026-93537

No comments yet


Leave a comment