PT-2026-94183 · Suse · Rancher-Extension-Stackstate+1
CVE-2026-44940
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SUSE Observability (affected versions not specified)
Description
The rancher-extension-stackstate extension exposes service tokens in plain configuration or insecure locations instead of managing them securely. This allows an attacker with minimal access to obtain the token, potentially leading to unauthorized access or privilege escalation within the observability environment.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Cleartext Storage of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Observability
Rancher-Extension-Stackstate