A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
{
"cna_assigner": "suse",
"cwe_ids": [
"CWE-290",
"CWE-639"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93538.json"
}{
"extracted_events": [
{
"introduced": "0.16.0"
},
{
"fixed": "0.16.1"
},
{
"introduced": "0.15.0"
},
{
"fixed": "0.15.6"
},
{
"introduced": "0.14.0"
},
{
"fixed": "0.14.10"
},
{
"introduced": "0.13.0"
},
{
"fixed": "0.13.15"
},
{
"introduced": "0.12.0"
},
{
"fixed": "0.12.19"
}
],
"source": "AFFECTED_FIELD"
}