CVE-2026-93540

Source
https://cve.org/CVERecord?id=CVE-2026-93540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93540
Aliases
  • GHSA-m93g-8438-2cgg
Published
2026-09-28T14:45:42Z
Modified
2026-09-30T03:47:28Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Fleet applies namespace labels and annotations without the bundle's service account privileges
Details

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.

This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.

Database specific
{
    "cna_assigner":  "suse",
    "cwe_ids":  [
        "CWE-266"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93540.json"
}
References

Affected packages

Git / github.com/rancher/fleet

Affected ranges

Type
GIT
Repo
https://github.com/rancher/fleet
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.16.0"
        },
        {
            "fixed":  "0.16.1"
        },
        {
            "introduced":  "0.15.0"
        },
        {
            "fixed":  "0.15.7"
        },
        {
            "introduced":  "0.14.0"
        },
        {
            "fixed":  "0.14.11"
        },
        {
            "introduced":  "0.13.0"
        },
        {
            "fixed":  "0.13.16"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

pkg/apis/v0.*
pkg/apis/v0.13.0
pkg/apis/v0.13.11
pkg/apis/v0.13.11-rc.1
pkg/apis/v0.13.11-rc.2
pkg/apis/v0.13.13
pkg/apis/v0.13.14
pkg/apis/v0.13.7
pkg/apis/v0.13.7-rc.1
pkg/apis/v0.13.7-rc.2
pkg/apis/v0.14.0
pkg/apis/v0.14.2
pkg/apis/v0.14.2-beta.1
pkg/apis/v0.14.2-rc.1
pkg/apis/v0.14.2-rc.2
pkg/apis/v0.14.6
pkg/apis/v0.14.6-rc.2
pkg/apis/v0.14.6-rc.3
pkg/apis/v0.14.8
pkg/apis/v0.14.9
pkg/apis/v0.15.0
pkg/apis/v0.15.2
pkg/apis/v0.15.2-rc.2
pkg/apis/v0.15.2-rc.3
pkg/apis/v0.15.4
pkg/apis/v0.15.5
pkg/apis/v0.16.0
pkg/apis/v0.16.1-beta.1
v0.*
v0.13.0
v0.13.0-rc.4
v0.13.1
v0.13.1-beta.1
v0.13.1-beta.2
v0.13.1-rc.1
v0.13.1-rc.2
v0.13.1-rc.3
v0.13.1-rc.4
v0.13.1-rc.5
v0.13.1-rc.6
v0.13.10
v0.13.10-beta.1
v0.13.10-beta.2
v0.13.10-beta.3
v0.13.10-beta.4
v0.13.10-beta.5
v0.13.10-rc.1
v0.13.10-rc.2
v0.13.11
v0.13.11-rc.1
v0.13.11-rc.2
v0.13.12
v0.13.12-rc.1
v0.13.13
v0.13.14
v0.13.14-rc.1
v0.13.14-rc.2
v0.13.15
v0.13.15-rc.1
v0.13.15-rc.2
v0.13.16-rc.1
v0.13.16-rc.2
v0.13.2
v0.13.2-rc.1
v0.13.2-rc.2
v0.13.3
v0.13.4
v0.13.4-rc.1
v0.13.4-rc.2
v0.13.5
v0.13.5-beta.1
v0.13.5-rc.1
v0.13.5-rc.2
v0.13.5-rc.3
v0.13.6
v0.13.6-beta.1
v0.13.6-rc.1
v0.13.7
v0.13.7-alpha.1
v0.13.7-alpha.2
v0.13.7-rc.1
v0.13.7-rc.2
v0.13.8
v0.13.8-rc.1
v0.13.9
v0.13.9-rc.1
v0.13.9-rc.3
v0.13.9-rc.4
v0.14.0
v0.14.1
v0.14.1-beta.1
v0.14.1-beta.2
v0.14.1-beta.3
v0.14.1-beta.4
v0.14.1-rc.1
v0.14.10
v0.14.10-rc.1
v0.14.10-rc.2
v0.14.11-rc.1
v0.14.11-rc.2
v0.14.2
v0.14.2-beta.1
v0.14.2-rc.1
v0.14.2-rc.2
v0.14.3
v0.14.3-beta.1
v0.14.3-rc.1
v0.14.3-rc.2
v0.14.3-rc.3
v0.14.4
v0.14.4-beta.1
v0.14.4-beta.2
v0.14.4-rc.1
v0.14.4-rc.2
v0.14.4-rc.3
v0.14.4-rc.4
v0.14.4-rc.5
v0.14.5
v0.14.5-beta.1
v0.14.5-beta.2
v0.14.5-beta.3
v0.14.5-beta.4
v0.14.5-beta.5
v0.14.5-rc.1
v0.14.5-rc.2
v0.14.6
v0.14.6-rc.1
v0.14.6-rc.2
v0.14.6-rc.3
v0.14.7
v0.14.7-rc.1
v0.14.7-rc.2
v0.14.8
v0.14.9
v0.14.9-rc.1
v0.14.9-rc.2
v0.15.0
v0.15.0-rc.6
v0.15.1
v0.15.1-beta.1
v0.15.1-beta.2
v0.15.1-beta.3
v0.15.1-beta.4
v0.15.1-rc.1
v0.15.1-rc.2
v0.15.2
v0.15.2-rc.1
v0.15.2-rc.2
v0.15.2-rc.3
v0.15.3
v0.15.3-beta.1
v0.15.3-beta.2
v0.15.3-rc.1
v0.15.3-rc.2
v0.15.4
v0.15.5
v0.15.5-rc.1
v0.15.5-rc.2
v0.15.6
v0.15.6-alpha.1
v0.15.6-rc.1
v0.15.7-rc.1
v0.15.7-rc.2
v0.16.0
v0.16.0-rc.5
v0.16.1-beta.1
v0.16.1-beta.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93540.json"