Vulnerability in SUSE Rancher Fleet's Git Webhook Receiver
CVE-2026-93539
5.4MEDIUM
What is CVE-2026-93539?
The Git webhook receiver in SUSE Rancher Fleet is vulnerable when the webhook secret is not properly configured. Under these circumstances, unauthorized webhook requests can be processed without verification. This flaw allows an attacker with network access to the webhook service to alter the spec.pollingInterval field of a GitRepo resource across all namespaces, enabling them to modify configurations outside their authorized access. This vulnerability impacts only SUSE Rancher Fleet versions prior to 0.16.2.
Affected Version(s)
Rancher 0.16.0 < 0.16.2