Path Traversal Vulnerability in Rancher Fleet Affects Multiple Versions
CVE-2026-44948

5.3MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
30 June 2026

What is CVE-2026-44948?

A path traversal vulnerability exists in the ImageScan subsystem of Rancher Fleet. This flaw allows attackers to manipulate file paths, enabling them to access directories and files outside of the intended directory structure. This behavior could lead to unauthorized access and potentially result in a denial of service, impacting system stability. Administrators using affected versions of Fleet should apply necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Rancher 0.12.0 < 0.12.16

Rancher 0.13.0 < 0.13.12

Rancher 0.14.0 < 0.14.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergey Kanibor
.