A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
{
"cwe_ids": [
"CWE-95"
],
"cna_assigner": "suse",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44939.json"
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "2.14.0"
},
{
"fixed": "2.14.2"
},
{
"introduced": "2.13.0"
},
{
"fixed": "2.13.6"
},
{
"introduced": "2.12.0"
},
{
"fixed": "2.12.10"
},
{
"introduced": "2.11.0"
},
{
"fixed": "2.11.14"
},
{
"introduced": "2.10.0"
},
{
"fixed": "2.10.12"
}
]
}