CVE-2026-44949 Details
Description
A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission payload and cause workspace-related Kubernetes objects to be created with attacker-chosen identity data.
A vulnerability exists in the Rancher FleetWorkspace admission process within the webhook handler. It affects Rancher Webhook versions 0.7.0 prior to 0.7.10, 0.8.0 prior to 0.8.7, 0.9.0 prior to 0.9.6, and 0.10.0 prior to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could send a crafted admission payload, leading to the creation of workspace-related Kubernetes objects with attacker-chosen identity data. This exploitation could cause unauthorized integrity changes in Fleet workspace role-based access control (RBAC) for newly created workspaces.
Users can upgrade to Rancher Webhook versions 0.10.7, 0.9.6, 0.8.7, or 0.7.10. The fix is included in Rancher releases 2.14.3, 2.13.7, 2.12.11, and 2.11.15. For more information, consult the Rancher webhook hardening guide and reach out to the SUSE Rancher Security team for security-related inquiries.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/webhook/security/advisories/GHSA-h83p-cq95-vph4 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |