Privilege Mismatch Vulnerability in Rancher Fleet by SUSE
CVE-2026-93540
6.5MEDIUM
What is CVE-2026-93540?
A privilege mismatch in SUSE Rancher Fleet allows unauthorized users to alter namespace labels and annotations without proper authorization checks. This occurs when a bundle requests metadata updates via the namespaceLabels and namespaceAnnotations options, potentially compromising the integrity of deployed namespaces. Versions below 0.16.2, 0.15.7, 0.14.11, and 0.13.16 are particularly vulnerable, with older versions likely affected as well.
Affected Version(s)
Rancher 0.16.0 < 0.16.1
Rancher 0.15.0 < 0.15.7
Rancher 0.14.0 < 0.14.11