CVE-2026-44949

Source
https://cve.org/CVERecord?id=CVE-2026-44949
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44949.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44949
Aliases
  • GHSA-h83p-cq95-vph4
Published
2026-06-30T14:41:34.007Z
Modified
2026-07-15T01:49:15.478691793Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N CVSS Calculator
Summary
Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook
Details

A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission payload and cause workspace-related Kubernetes objects to be created with attacker-chosen identity data.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44949.json",
    "cna_assigner": "suse",
    "cwe_ids": [
        "CWE-306"
    ]
}
References

Affected packages

Git / github.com/rancher/webhook

Affected ranges

Type
GIT
Repo
https://github.com/rancher/webhook
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.7.0"
        },
        {
            "fixed": "0.7.10"
        },
        {
            "introduced": "0.8.0"
        },
        {
            "fixed": "0.8.7"
        },
        {
            "introduced": "0.9.0"
        },
        {
            "fixed": "0.9.6"
        },
        {
            "introduced": "0.10.0"
        },
        {
            "fixed": "0.10.7"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.7.4-rc.2
v0.*
v0.7.0
v0.7.0-rc.12
v0.7.1
v0.7.1-rc.1
v0.7.1-rc.2
v0.7.1-rc.3
v0.7.1-rc.4
v0.7.1-rc.5
v0.7.10-rc.1
v0.7.10-rc.10
v0.7.10-rc.11
v0.7.10-rc.2
v0.7.10-rc.3
v0.7.10-rc.4
v0.7.10-rc.5
v0.7.10-rc.6
v0.7.10-rc.7
v0.7.10-rc.8
v0.7.10-rc.9
v0.7.2
v0.7.2-rc.1
v0.7.2-rc.2
v0.7.3
v0.7.3-rc.1
v0.7.3-rc.2
v0.7.3-rc.3
v0.7.4
v0.7.4-rc.1
v0.7.4-rc.2
v0.7.5
v0.7.5-rc.1
v0.7.5-rc.2
v0.7.5-rc.3
v0.7.6
v0.7.6-rc.1
v0.7.6-rc.2
v0.7.6-rc.3
v0.7.7
v0.7.7-rc.1
v0.7.8
v0.7.8-rc.1
v0.7.9
v0.7.9-rc.1
v0.8.0
v0.8.0-rc.14
v0.8.1
v0.8.1-rc.1
v0.8.1-rc.2
v0.8.1-rc.3
v0.8.2
v0.8.2-rc.1
v0.8.2-rc.2
v0.8.2-rc.3
v0.8.2-rc.4
v0.8.3
v0.8.3-rc.1
v0.8.4
v0.8.4-rc.1
v0.8.5
v0.8.5-rc.1
v0.8.5-rc.2
v0.8.6
v0.8.6-rc.1
v0.8.7-rc.1
v0.8.7-rc.2
v0.8.7-rc.3
v0.8.7-rc.4
v0.8.7-rc.5
v0.8.7-rc.6
v0.8.7-rc.7
v0.8.7-rc.8
v0.8.7-rc.9
v0.9.0
v0.9.1
v0.9.2
v0.9.2-rc.1
v0.9.2-rc.2
v0.9.2-rc.3
v0.9.3
v0.9.4
v0.9.4-rc.1
v0.9.5
v0.9.5-rc.1
v0.9.5-rc.2
v0.9.5-rc.3
v0.9.5-rc.4
v0.9.5-rc.5
v0.9.5-rc.6
v0.9.6-rc.1
v0.9.6-rc.2
v0.9.6-rc.3
v0.9.6-rc.4
v0.9.6-rc.5
v0.9.6-rc.6
v0.9.6-rc.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44949.json"