CVE-2026-93538
Received
Received - Intake
Authorization Bypass in SUSE Rancher Fleet
Vulnerability report for CVE-2026-93538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-28
Last updated on: 2026-09-28
Assigner: SUSE
Description
Description
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.
This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| suse | rancher_fleet | to 0.16.1 (exc) |
| suse | rancher_fleet | to 0.15.6 (exc) |
| suse | rancher_fleet | to 0.14.10 (exc) |
| suse | rancher_fleet | to 0.13.15 (exc) |
| suse | rancher_fleet | to 0.12.19 (exc) |
| suse | rancher_fleet | From 0.12.0 (inc) to 0.16.1 (exc) |
| suse | rancher_fleet | From 0.13.0 (inc) to 0.13.15 (exc) |
| suse | rancher_fleet | From 0.14.0 (inc) to 0.14.10 (exc) |
| suse | rancher_fleet | From 0.15.0 (inc) to 0.15.6 (exc) |
| suse | rancher_fleet | From 0.16.0 (inc) to 0.16.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |