CVE-2026-88808

Source
https://cve.org/CVERecord?id=CVE-2026-88808
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88808.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88808
Aliases
  • GHSA-q9v4-358v-r8q5
Published
2026-09-28T15:36:13Z
Modified
2026-09-29T03:47:24Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
Details

A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.

This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-250"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88808.json"
}
References

Affected packages

Git / github.com/rancher/fleet

Affected ranges

Type
GIT
Repo
https://github.com/rancher/fleet
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.16.0"
        },
        {
            "fixed":  "0.16.2"
        },
        {
            "introduced":  "0.15.0"
        },
        {
            "fixed":  "0.15.7"
        },
        {
            "introduced":  "0.14.0"
        },
        {
            "fixed":  "0.14.11"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

pkg/apis/v0.*
pkg/apis/v0.14.0
pkg/apis/v0.14.2
pkg/apis/v0.14.2-beta.1
pkg/apis/v0.14.2-rc.1
pkg/apis/v0.14.2-rc.2
pkg/apis/v0.14.6
pkg/apis/v0.14.6-rc.2
pkg/apis/v0.14.6-rc.3
pkg/apis/v0.14.8
pkg/apis/v0.14.9
pkg/apis/v0.15.0
pkg/apis/v0.15.2
pkg/apis/v0.15.2-rc.2
pkg/apis/v0.15.2-rc.3
pkg/apis/v0.15.4
pkg/apis/v0.15.5
pkg/apis/v0.16.0
pkg/apis/v0.16.1
pkg/apis/v0.16.1-beta.1
pkg/apis/v0.16.1-rc.1
pkg/helmvalues/v0.*
pkg/helmvalues/v0.16.1
pkg/helmvalues/v0.16.1-rc.1
v0.*
v0.14.0
v0.14.1
v0.14.1-beta.1
v0.14.1-beta.2
v0.14.1-beta.3
v0.14.1-beta.4
v0.14.1-rc.1
v0.14.10
v0.14.10-rc.1
v0.14.10-rc.2
v0.14.11-rc.1
v0.14.11-rc.2
v0.14.2
v0.14.2-beta.1
v0.14.2-rc.1
v0.14.2-rc.2
v0.14.3
v0.14.3-beta.1
v0.14.3-rc.1
v0.14.3-rc.2
v0.14.3-rc.3
v0.14.4
v0.14.4-beta.1
v0.14.4-beta.2
v0.14.4-rc.1
v0.14.4-rc.2
v0.14.4-rc.3
v0.14.4-rc.4
v0.14.4-rc.5
v0.14.5
v0.14.5-beta.1
v0.14.5-beta.2
v0.14.5-beta.3
v0.14.5-beta.4
v0.14.5-beta.5
v0.14.5-rc.1
v0.14.5-rc.2
v0.14.6
v0.14.6-rc.1
v0.14.6-rc.2
v0.14.6-rc.3
v0.14.7
v0.14.7-rc.1
v0.14.7-rc.2
v0.14.8
v0.14.9
v0.14.9-rc.1
v0.14.9-rc.2
v0.15.0
v0.15.0-rc.6
v0.15.1
v0.15.1-beta.1
v0.15.1-beta.2
v0.15.1-beta.3
v0.15.1-beta.4
v0.15.1-rc.1
v0.15.1-rc.2
v0.15.2
v0.15.2-rc.1
v0.15.2-rc.2
v0.15.2-rc.3
v0.15.3
v0.15.3-beta.1
v0.15.3-beta.2
v0.15.3-rc.1
v0.15.3-rc.2
v0.15.4
v0.15.5
v0.15.5-rc.1
v0.15.5-rc.2
v0.15.6
v0.15.6-alpha.1
v0.15.6-rc.1
v0.15.7-rc.1
v0.15.7-rc.2
v0.16.0
v0.16.0-rc.5
v0.16.1
v0.16.1-beta.1
v0.16.1-beta.2
v0.16.1-rc.1
v0.16.1-rc.2
v0.16.2-rc.1
v0.16.2-rc.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88808.json"