PT-2026-50872 · Suse · Rancher Manager

·

CVE-2026-44939

·

Published

2026-06-19

·

Updated

2026-07-30

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rancher Manager versions prior to 2.14.2
Description A command injection issue exists in the import endpoint "/v3/import/{token} {clusterId}.yaml". This occurs due to unsanitized YAML parameters, which could allow remote attackers to break out of an image and execute malicious containers.
Recommendations Update to version 2.14.2 or later.

Exploit

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44939
GHSA-MHC6-2GFQ-XX62
GO-2026-5875
OPENSUSE-SU-2026:21483-1

Affected Products

Rancher Manager