Vulnerability in SUSE Rancher Fleet's Git Webhook Receiver
CVE-2026-93539

5.4MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-93539?

The Git webhook receiver in SUSE Rancher Fleet is vulnerable when the webhook secret is not properly configured. Under these circumstances, unauthorized webhook requests can be processed without verification. This flaw allows an attacker with network access to the webhook service to alter the spec.pollingInterval field of a GitRepo resource across all namespaces, enabling them to modify configurations outside their authorized access. This vulnerability impacts only SUSE Rancher Fleet versions prior to 0.16.2.

Affected Version(s)

Rancher 0.16.0 < 0.16.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/Pig-Tail
.