Service Token Exposure in SUSE Observability Extension by StackVista
CVE-2026-44940
5.7MEDIUM
What is CVE-2026-44940?
The rancher-extension-stackstate extension within SUSE Observability has a critical security flaw that exposes service tokens in plain text, either in configuration files or insecure locations. This oversight allows unauthorized individuals with minimal access to acquire sensitive tokens, potentially leading to privilege escalation and unauthorized access within the observability framework. It is essential for users to mitigate this vulnerability by implementing stronger security measures around token management.
Affected Version(s)
SUSE Observability 0 < 2.13.6
SUSE Observability 2.14.0 < 2.14.2