


Perceptive Security
SOC/SIEM Consultancy

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 18:03:40
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
A missing validation vulnerability exists in the Helm Deployer component of SUSE Rancher Fleet affecting versions 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11, and 0.12 before 0.12.15. The flaw involves improper validation of 'valuesFrom' references, which can be exploited by owners of one tenant to access fleet credentials belonging to other tenants. This represents a cross-tenant credential exposure risk in multi-tenant Rancher Fleet deployments. The vulnerability has been assigned CVE-2026-44935 and is currently awaiting full analysis on NVD. Patched versions have been released for all affected branches. Organizations using SUSE Rancher Fleet in multi-tenant configurations should upgrade immediately to mitigate the risk of credential theft.
Technical details
Mitigation steps:
Affected products:
SUSE Rancher Fleet 0.15
SUSE Rancher Fleet 0.14
SUSE Rancher Fleet 0.13
SUSE Rancher Fleet 0.12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44935
https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
