PT-2026-99904 · Suse · Rancher Fleet

·

CVE-2026-93538

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SUSE Rancher Fleet versions prior to 0.16.1 SUSE Rancher Fleet versions prior to 0.15.6 SUSE Rancher Fleet versions prior to 0.14.10 SUSE Rancher Fleet versions prior to 0.13.15 SUSE Rancher Fleet versions prior to 0.12.19
Description A cross-tenant authorization issue exists during agent-initiated cluster registration. Cluster labels provided by the registering agent, including those in the reserved management.cattle.io/ namespace (such as the cluster display name label), are applied to the resulting upstream Cluster object. Since Fleet uses these labels to resolve GitRepo and Bundle targets, a user registering a cluster into a shared Fleet workspace namespace could manipulate labels to satisfy targeting rules intended for a different cluster.
Recommendations Update to version 0.16.1 or newer. Update to version 0.15.6 or newer. Update to version 0.14.10 or newer. Update to version 0.13.15 or newer. Update to version 0.12.19 or newer.

Exploit

Fix

Authentication Bypass by Spoofing

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93538
GHSA-H9P5-FP5H-QPQR

Affected Products

Rancher Fleet