CVE-2026-88808
Received Received - Intake

Privilege Escalation in SUSE Rancher Fleet

Vulnerability report for CVE-2026-88808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: SUSE

Description

A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
suse rancher_fleet to 0.16.2 (exc)
suse rancher_fleet to 0.15.7 (exc)
suse rancher_fleet to 0.14.11 (exc)
suse rancher to 2.15.2 (exc)
suse rancher to 2.14.6 (exc)
suse rancher to 2.13.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Rancher Manager's Fleet agent in multi-tenant environments. The Fleet agent writes resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount assigned to the deployment. This allows tenants with access to create Fleet resources to overwrite Secrets and ConfigMaps in any namespace, including creating new namespaces.

Detection Guidance

Check Fleet agent logs for unauthorized resource writes to downstream clusters. Look for unexpected Secrets or ConfigMaps in namespaces not managed by the ServiceAccount. Verify Fleet versions against affected ranges (0.14.0-0.14.11, 0.15.0-0.15.7, 0.16.0-0.16.2).

Commands: kubectl get fleetagent -A; kubectl logs -n cattle-fleet-system fleet-agent-xxxx; kubectl get secrets,configmaps -A | grep -v expected-namespaces

Impact Analysis

An attacker with access to create Fleet resources could overwrite configuration files, redirect image pulls to malicious registries, or compromise TLS and database secrets. This could lead to unauthorized access, workload disruption, or data breaches in shared downstream clusters.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality and integrity requirements in GDPR and HIPAA. Overwritten secrets or configs may expose sensitive data, leading to compliance violations and potential legal consequences.

Mitigation Strategies

Upgrade Fleet to patched versions (0.14.11, 0.15.7, 0.16.2) and Rancher to v2.13.10, v2.14.6, or v2.15.2. Disable Fleet resource creation via RBAC or disable the feature entirely as a workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart