๐Ÿ” CVE Alert

CVE-2026-44939

UNKNOWN 0.0

Command injection through unsanitized YAML parameter in Rancher

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

CWE CWE-95
Vendor suse
Product rancher
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for suse rancher

Be the first to know when new unknown vulnerabilities affecting suse rancher are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SUSE / Rancher
2.14.0 < 2.14.2 2.13.0 < 2.13.6 2.12.0 < 2.12.10 2.11.0 < 2.11.14 2.10.0 < 2.10.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rancher/rancher/security/advisories/GHSA-mhc6-2gfq-xx62