PT-2026-94183 · Suse · Rancher-Extension-Stackstate+1

CVE-2026-44940

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SUSE Observability (affected versions not specified)
Description The rancher-extension-stackstate extension exposes service tokens in plain configuration or insecure locations instead of managing them securely. This allows an attacker with minimal access to obtain the token, potentially leading to unauthorized access or privilege escalation within the observability environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Cleartext Storage of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44940

Affected Products

Suse Observability
Rancher-Extension-Stackstate