CVE-2026-93538
Received Received - Intake

Authorization Bypass in SUSE Rancher Fleet

Vulnerability report for CVE-2026-93538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: SUSE

Description

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
suse rancher_fleet to 0.16.1 (exc)
suse rancher_fleet to 0.15.6 (exc)
suse rancher_fleet to 0.14.10 (exc)
suse rancher_fleet to 0.13.15 (exc)
suse rancher_fleet to 0.12.19 (exc)
suse rancher_fleet From 0.12.0 (inc) to 0.16.1 (exc)
suse rancher_fleet From 0.13.0 (inc) to 0.13.15 (exc)
suse rancher_fleet From 0.14.0 (inc) to 0.14.10 (exc)
suse rancher_fleet From 0.15.0 (inc) to 0.15.6 (exc)
suse rancher_fleet From 0.16.0 (inc) to 0.16.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a cross-tenant authorization issue in SUSE Rancher Fleet where an attacker can manipulate cluster labels during registration to trick Fleet into applying those labels to a cluster object. Since Fleet uses cluster labels to determine which workloads to deploy, the attacker can cause their cluster to receive workloads intended for another tenant, leading to unauthorized access to manifests, secrets, and deployments.

Detection Guidance

Check Rancher Fleet versions for affected releases (0.12.0 to 0.16.0). Inspect cluster labels in shared Fleet workspace namespaces for unexpected or reserved labels like management.cattle.io/. Verify agent-initiated registrations and label-based targeting rules.

Impact Analysis

If you are a tenant sharing a Fleet workspace namespace, an attacker could register a malicious cluster that receives your workloads, exposing your bundle manifests, resolved Helm values, and secrets. This could result in unauthorized workload deployment on the attacker's cluster and potential data leakage or service disruption.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Exposure of secrets and workloads to unintended parties may result in compliance breaches, data breaches, and failure to meet regulatory standards for data protection and access control.

Mitigation Strategies

Upgrade Rancher Fleet to patched versions (v0.12.19, v0.13.15, v0.14.10, v0.15.6, or v0.16.1). Use dedicated workspace namespaces for each tenant. Disable label copying from agents or switch to manager-initiated registration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart