Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93539— Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver

Quick assessment

Affected
SUSE Rancher
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Fleet 的 Git Webhook 接收器(即 gitjob Webhook 服务)中发现了一个漏洞。当未配置 Webhook 密钥时,传入的 Webhook 请求未经任何验证即被接受。处理此类请求可能会导致匹配到的 GitRepo 资源中的 spec.pollingInterval 字段发生更改,且该影响可波及任意命名空间(namespace)中的资源。因此,任何拥有对 Webhook 服务网络访问权限但无 Kubernetes 凭据的调用者,都可以修改其未被授权访问的命名空间之外的 GitRepo 配置

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93539

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Rancher 0.16.0 ~ 0.16.2 -

II. Public POCs for CVE-2026-93539

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93539

请登录查看更多情报信息。

Other References for CVE-2026-93539 (1)

Same Patch Batch · SUSE · 2026-09-28 · 5 CVEs total

CVE-2026-78424 8.8 HIGH OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o
CVE-2026-93538 7.1 HIGH Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen
CVE-2026-93540 6.5 MEDIUM Fleet applies namespace labels and annotations without the bundle's service account privil
CVE-2026-93537 6.5 MEDIUM Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir

IV. Related Vulnerabilities

V. Comments for CVE-2026-93539

No comments yet


Leave a comment