๐Ÿ” CVE Alert

CVE-2026-44940

MEDIUM 5.7

Service token exposure and potential privilege escalation in SUSE Observability

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.

CWE CWE-312 CWE-200
Vendor suse
Product suse observability
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for suse suse observability

Be the first to know when new medium vulnerabilities affecting suse suse observability are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

SUSE / SUSE Observability
0 < 2.13.6 2.14.0 < 2.14.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44940 github.com: https://github.com/StackVista/rancher-extension-stackstate/security/advisories/GHSA-7c27-jc6w-pw95