CVE-2026-44948 Details
Description
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.
A path traversal vulnerability has been identified in the ImageScan subsystem of Rancher Fleet versions 0.12.0 prior to 0.12.16, 0.13.0 prior to 0.13.12, 0.14.0 prior to 0.14.7, and 0.15.0 prior to 0.15.3. This vulnerability allows an authenticated user with permission to create or modify GitRepo resources to traverse outside the intended directory. The exploitation of this vulnerability causes resource exhaustion, leading to a denial-of-service condition in the ImageScan subsystem.
Users can upgrade to Rancher Fleet versions 0.12.16, 0.13.12, 0.14.7, or 0.15.3, where this vulnerability has been patched. For Fleet v0.15, the ImageScan feature can be disabled by setting 'imagescan.enabled=false' in the Helm chart values. Additionally, users can restrict the creation or modification of GitRepo resources through Kubernetes RBAC to prevent untrusted users from exploiting this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/fleet/security/advisories/GHSA-c45g-6c2c-rj3p | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |