PT-2026-50872 · Suse · Rancher

Michael Wollner

+1

·

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-44939

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Rancher Manager versions prior to 2.14.2
Description A command injection issue exists in the import endpoint "/v3/import/{token} {clusterId}.yaml". This occurs due to unsanitized YAML parameters, which could allow remote attackers to break out of an image and execute malicious containers.
Recommendations Update to version 2.14.2 or later.

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44939

Affected Products

Rancher