CVE-2026-44934 Details
Description
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.
A vulnerability allowing information disclosure has been identified in SUSE Rancher AI Agent versions 1.0.0 prior to 1.0.2. When the DEBUG log level is enabled, sensitive data such as API keys and Model Context Protocol (MCP) responses may be leaked into log files. This exposure could be exploited by local attackers to misuse the disclosed data or credentials.
Users can upgrade to SUSE Rancher AI Agent version 1.0.2, where this vulnerability has been patched. If an immediate upgrade is not possible, it is recommended to disable DEBUG logging and use the default INFO logging level to prevent sensitive data from being logged.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/rancher-ai-agent/security/advisories/GHSA-5r2r-h824-fr5v | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-215 | Insertion of Sensitive Information Into Debugging Code | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | New CVE Received | [email protected] |