CVE-2026-93540
Received Received - Intake

Privilege Escalation in SUSE Rancher Fleet

Vulnerability report for CVE-2026-93540, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: SUSE

Description

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
suse rancher_fleet to 0.16.2 (exc)
suse rancher_fleet to 0.15.7 (exc)
suse rancher_fleet to 0.14.11 (exc)
suse rancher_fleet to 0.13.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A privilege mismatch in Fleet allowed bundles to modify namespace labels and annotations without proper authorization. When a bundle requested these changes, the update bypassed the same access controls applied to the rest of the bundle's deployment. This meant a bundle could alter namespace metadata even if the identity it was pinned to lacked permission to modify that namespace.

Detection Guidance

Check Fleet versions for affected releases (0.13.0-0.13.16, 0.14.0-0.14.11, 0.15.0-0.15.7, 0.16.0-0.16.1). Review namespace metadata changes in multi-tenant deployments where bundles use pinned service accounts.

Impact Analysis

In multi-tenant deployments, this could let unauthorized users change namespace labels or annotations, potentially disrupting configurations or bypassing security policies. It does not expose confidential data or directly affect workload availability.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to namespace metadata, which may violate access control requirements in standards like GDPR or HIPAA. Unauthorized changes could undermine audit trails or security configurations.

Mitigation Strategies
  • Upgrade Fleet to patched versions (0.13.16, 0.14.11, 0.15.7, 0.16.1 or later).
  • If upgrading is not possible, restrict who can deploy through Fleet or limit permissions for GitRepo, HelmOp, and Bundle resources.
  • Block namespace metadata changes by the Fleet agent using an admission or policy controller.
  • For multi-tenant setups, explicitly grant tenant service accounts required namespace permissions or pre-create namespaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart