CVE-2026-44935
published 2026-07-02CVE-2026-44935: Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12…
PriorityP260critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.58%
43.9th percentile
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | rancher_fleet | >= 0.12.0 < 0.12.15 | 0.12.15 |
| github.com | rancher_fleet | >= 0.13.0 < 0.13.11 | 0.13.11 |
| github.com | rancher_fleet | >= 0.14.0 < 0.14.6 | 0.14.6 |
| github.com | rancher_fleet | >= 0.15.0 < 0.15.2 | 0.15.2 |
| suse | rancher | >= 0.12.0 < 0.12.15 | 0.12.15 |
| suse | rancher | >= 0.13.0 < 0.13.11 | 0.13.11 |
| suse | rancher | >= 0.14.0 < 0.14.6 | 0.14.6 |
| suse | rancher | >= 0.15.0 < 0.15.2 | 0.15.2 |
| suse | rancher_fleet | >= 0.12.0 < 0.12.15 | 0.12.15 |
| suse | rancher_fleet | >= 0.13.0 < 0.13.11 | 0.13.11 |
| suse | rancher_fleet | >= 0.14.0 < 0.14.6 | 0.14.6 |
| suse | rancher_fleet | >= 0.15.0 < 0.15.2 | 0.15.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SUSE Rancher up to 0.12.14/0.13.10/0.14.5/0.15.1 improper validation of specified type of input (EUVD-2026-41408)
vuldb·2026-07-02·CVSS 9.9
CVE-2026-44935 [CRITICAL] SUSE Rancher up to 0.12.14/0.13.10/0.14.5/0.15.1 improper validation of specified type of input (EUVD-2026-41408)
A vulnerability was found in SUSE Rancher up to 0.12.14/0.13.10/0.14.5/0.15.1 and classified as problematic. Impacted is an unknown function. Such manipulation leads to improper validation of specified type of input.
This vulnerability is traded as CVE-2026-44935. Access to the local network is required for this attack to succeed. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
ghsa·2026-07-01
CVE-2026-44935 [CRITICAL] CWE-863 Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
### Impact
A vulnerability in Fleet for Rancher Manager affects multi-tenancy environments where different tenants share the same downstream clusters (e.g., different privileged or untrusted teams inside the same organization).
On unpatched versions, tenants could bypass restrictions to access any config map or secret across all namespaces on the downstream cluster. They can create cluster-wide resources using `HelmOp` or `Bundle` without authorization.
Specifically, an attacker can exploit this vulnerability in the following ways:
1. Use `valuesFrom` in `fleet.yaml`(through a `GitRepo` resource) or a `HelmOp resource to read the contents of any secret an on the downstre
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-02
Published