CVE-2026-44936
Last modified
CVE-2026-44936 is a medium-severity vulnerability rated 5/10 on the CVSS scale. Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Rancher Fleet | >= 0.12.0, < 0.12.15 |
| Suse | Rancher Fleet | >= 0.13.0, < 0.13.11 |
| Suse | Rancher Fleet | >= 0.14.0, < 0.14.6 |
| Suse | Rancher Fleet | >= 0.15.0, < 0.15.2 |
References
- https://github.com/advisories/GHSA-hx4v-cxpf-vh8mExploit, Third Party Advisory, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44936?
How severe is CVE-2026-44936?
How do I fix CVE-2026-44936?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44930An LDAP injection vulnerability in the LDAP Certificate repo…9.8
- CVE-2026-44931The newly introduced RecordUsage D-Bus method https://gitla…5.1
- CVE-2026-44932Passing of unsanitized strings from DHCP replies into the wi…8.8
- CVE-2026-44933`PluginScript` attempts to `chroot` the plugin to the `repoM…8.5
- CVE-2026-44934A information disclosure when DEBUG loglevel is set in SUSE …7
- CVE-2026-44935Missing validation of "valuesFrom" references in Helm Deploy…9.9
- CVE-2026-44937Potential forgery of webhook requests when using a unauthent…8.2
- CVE-2026-44938A vulnerability has been identified in Fleet's agent-side de…8.8
- CVE-2026-44939A command injection vulnerability in the Rancher Manager clu…9.4
- CVE-2026-4494A vulnerability was identified in atjiu pybbs 6.0.0. This af…3.5
- CVE-2026-44941A relative path traversal in the "keyhint" option in repomd.…8.8
- CVE-2026-44942A path traversal in handling the "path" component of .repo f…6.5
Are you affected by CVE-2026-44936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
