Service Token Exposure in SUSE Observability Extension by StackVista
CVE-2026-44940

5.7MEDIUM

Key Information:

Vendor

Suse

Vendor
CVE Published:
17 September 2026

What is CVE-2026-44940?

The rancher-extension-stackstate extension within SUSE Observability has a critical security flaw that exposes service tokens in plain text, either in configuration files or insecure locations. This oversight allows unauthorized individuals with minimal access to acquire sensitive tokens, potentially leading to privilege escalation and unauthorized access within the observability framework. It is essential for users to mitigate this vulnerability by implementing stronger security measures around token management.

Affected Version(s)

SUSE Observability 0 < 2.13.6

SUSE Observability 2.14.0 < 2.14.2

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.