CVE-2026-93539

Source
https://cve.org/CVERecord?id=CVE-2026-93539
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93539.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93539
Aliases
  • GHSA-8vfv-33cg-g75q
Published
2026-09-28T14:19:55Z
Modified
2026-09-30T03:47:28Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
Details

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any namespace. A caller with network access to the webhook service and no Kubernetes credentials can therefore alter GitRepo configuration outside

the namespaces they are authorized for.  This only affects SUSE Rancher Fleet 0.16 before 0.16.2, older versions are not affected.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93539.json"
}
References

Affected packages

Git / github.com/rancher/fleet

Affected ranges

Type
GIT
Repo
https://github.com/rancher/fleet
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.16.0"
        },
        {
            "fixed":  "0.16.2"
        },
        {
            "introduced":  "0.16"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

pkg/apis/v0.*
pkg/apis/v0.16.0
pkg/apis/v0.16.1
pkg/apis/v0.16.1-beta.1
pkg/apis/v0.16.1-rc.1
pkg/helmvalues/v0.*
pkg/helmvalues/v0.16.1
pkg/helmvalues/v0.16.1-rc.1
v0.*
v0.16.0
v0.16.0-rc.5
v0.16.1
v0.16.1-beta.1
v0.16.1-beta.2
v0.16.1-rc.1
v0.16.1-rc.2
v0.16.2-rc.1
v0.16.2-rc.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93539.json"