← Vulnerability feed

Vulnerability record · CVE-2026-93538 · published 28 September 2026

CVE-2026-93538: Suse rancher fleet authentication bypass by spoofing vulnerability

Suse · Rancher Fleet

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

7.1 CVSS 3.1 High EPSS 0.17% · top 94.1% CWE-290 · Authentication bypass by spoofingCWE-639 · Insecure direct object reference
7.1CVSS 3.1 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
7 Oct 2026Last modified by NVD

Description

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-93538 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-44935Suse rancher fleet vulnerabilityMissing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …EPSS 0.49%8.8CVE-2026-88808Suse rancher fleet execution with unnecessary privileges vulnerabilityA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin c…EPSS 0.27%8.3CVE-2026-44937Suse rancher fleet server-side request forgery (ssrf) vulnerabilityPotential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before …EPSS 0.42%6.5CVE-2026-93540Suse rancher fleet vulnerabilityA privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations…EPSS 0.17%6.5CVE-2026-93537Suse rancher fleet relative path traversal vulnerabilityA user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to …EPSS 0.30%5.4CVE-2026-93539Suse rancher fleet missing authentication for critical function vulnerabilityA vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhoo…EPSS 0.23%5.3CVE-2026-75036Suse rancher fleet server-side request forgery (ssrf) vulnerabilityA security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network …EPSS 0.36%5.0CVE-2026-44936Suse rancher fleet server-side request forgery (ssrf) vulnerabilityMissing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-93538), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.