CVE-2026-88808
HIGH
8,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.
This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
250
Execution with Unnecessary Privileges
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Read Application Data
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
AI/ML, Mobile
https://github.com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5