← Vulnerability feed

Vulnerability record · CVE-2026-93539 · published 28 September 2026

CVE-2026-93539: Suse rancher fleet missing authentication for critical function vulnerability

Suse · Rancher Fleet

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.

5.4 CVSS 3.1 Medium EPSS 0.23% · top 87.0% CWE-306 · Missing authentication for critical function
5.4CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
7 Oct 2026Last modified by NVD

Description

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-93539 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-44935Suse rancher fleet vulnerabilityMissing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …EPSS 0.49%8.8CVE-2026-88808Suse rancher fleet execution with unnecessary privileges vulnerabilityA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin c…EPSS 0.27%8.3CVE-2026-44937Suse rancher fleet server-side request forgery (ssrf) vulnerabilityPotential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before …EPSS 0.42%7.1CVE-2026-93538Suse rancher fleet authentication bypass by spoofing vulnerabilityA cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the …EPSS 0.17%6.5CVE-2026-93540Suse rancher fleet vulnerabilityA privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations…EPSS 0.17%6.5CVE-2026-93537Suse rancher fleet relative path traversal vulnerabilityA user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to …EPSS 0.30%5.3CVE-2026-75036Suse rancher fleet server-side request forgery (ssrf) vulnerabilityA security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network …EPSS 0.36%5.0CVE-2026-44936Suse rancher fleet server-side request forgery (ssrf) vulnerabilityMissing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-93539), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.