← Vulnerability feed

Vulnerability record · CVE-2026-93540 · published 28 September 2026

CVE-2026-93540: Suse rancher fleet vulnerability

Suse · Rancher Fleet

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.

6.5 CVSS 3.1 Medium EPSS 0.17% · top 93.7% CWE-266 · CWE-266
6.5CVSS 3.1 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
7 Oct 2026Last modified by NVD

Description

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-93540 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-44935Suse rancher fleet vulnerabilityMissing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …EPSS 0.49%8.8CVE-2026-88808Suse rancher fleet execution with unnecessary privileges vulnerabilityA vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin c…EPSS 0.27%8.3CVE-2026-44937Suse rancher fleet server-side request forgery (ssrf) vulnerabilityPotential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before …EPSS 0.42%7.1CVE-2026-93538Suse rancher fleet authentication bypass by spoofing vulnerabilityA cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the …EPSS 0.17%6.5CVE-2026-93537Suse rancher fleet relative path traversal vulnerabilityA user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to …EPSS 0.30%5.4CVE-2026-93539Suse rancher fleet missing authentication for critical function vulnerabilityA vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhoo…EPSS 0.23%5.3CVE-2026-75036Suse rancher fleet server-side request forgery (ssrf) vulnerabilityA security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network …EPSS 0.36%5.0CVE-2026-44936Suse rancher fleet server-side request forgery (ssrf) vulnerabilityMissing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-93540), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.