PT-2026-99912 · Suse · Rancher Fleet

·

CVE-2026-93540

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SUSE Rancher Fleet versions prior to 0.16.2 SUSE Rancher Fleet versions prior to 0.15.7 SUSE Rancher Fleet versions prior to 0.14.11 SUSE Rancher Fleet versions prior to 0.13.16
Description A privilege mismatch exists where updates to namespace metadata are not subject to the same authorization checks as the rest of a bundle's deployment. This occurs when a bundle requests namespace labels or annotations using the namespaceLabels and namespaceAnnotations options, allowing a bundle to modify labels and annotations on a target namespace even if the pinned identity lacks the necessary authorization to modify that namespace.
Recommendations Update to version 0.16.2 or later. Update to version 0.15.7 or later. Update to version 0.14.11 or later. Update to version 0.13.16 or later.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93540
GHSA-M93G-8438-2CGG

Affected Products

Rancher Fleet