Security Advisory

CVE-2026-44949

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-30 14:41:34
Last updated 2026-06-30 15:10:17
Assigner suse
CVSS score 7.0
State PUBLISHED

Description

A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission payload and cause workspace-related Kubernetes objects to be created with attacker-chosen identity data.