Security Advisory

CVE-2026-44935

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-02 16:00:06
Last updated 2026-07-03 03:56:15
Assigner suse
CVSS score 9.9
State PUBLISHED

Description

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.