CVE-2026-88808
Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
| CWE | CWE-250 |
| Vendor | suse |
| Product | rancher |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for suse rancher
Be the first to know when new high vulnerabilities affecting suse rancher are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
SUSE / Rancher
0.16.0 < 0.16.2 0.15.0 < 0.15.7 0.14.0 < 0.14.11