Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93538— Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet

Quick assessment

Affected
SUSE Rancher
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 SUSE Rancher Fleet 中发现了一个跨租户授权问题。在由代理(Agent)发起的集群注册过程中,注册代理所提供的集群标签(包括属于保留命名空间 的标签,例如集群显示名称标签)会被应用到最终生成的上游 Cluster 对象中。由于 Fleet 会基于这些集群标签来解析 GitRepo 和 Bundle 的目标集群,因此,能够向其他租户共享的 Fleet 工作区命名空间中注册集群的一方,可以使其自身的集群满足管理员本意为其他集群设定的目标匹配规则,从而导致未授权的资源部署或数据访问。 该漏洞影响 SU

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93538

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet
Source: CVE Program / CVE List V5
Vulnerability Description
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Rancher 0.16.0 ~ 0.16.1 -

II. Public POCs for CVE-2026-93538

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93538

请登录查看更多情报信息。

Other References for CVE-2026-93538 (1)

Same Patch Batch · SUSE · 2026-09-28 · 5 CVEs total

CVE-2026-78424 8.8 HIGH OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o
CVE-2026-93540 6.5 MEDIUM Fleet applies namespace labels and annotations without the bundle's service account privil
CVE-2026-93537 6.5 MEDIUM Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir
CVE-2026-93539 5.4 MEDIUM Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver

IV. Related Vulnerabilities

V. Comments for CVE-2026-93538

No comments yet


Leave a comment