CVE-2026-93538
Last modified
CVE-2026-93538 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object.
Description
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SUSE | Rancher | >= 0.16.0, < 0.16.1; >= 0.15.0, < 0.15.6; >= 0.14.0, < 0.14.10; >= 0.13.0, < 0.13.15; >= 0.12.0, < 0.12.19 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-93538?
How severe is CVE-2026-93538?
How do I fix CVE-2026-93538?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9353A security vulnerability has been detected in NousResearch h…7.3
- CVE-2026-93531A weakness has been identified in gedelumbung HospitalManage…4.3
- CVE-2026-93532A security vulnerability has been detected in gedelumbung Ho…6.3
- CVE-2026-93533A vulnerability was determined in spatie Scotty up to 1.4.4.…6.3
- CVE-2026-93534A vulnerability was identified in spatie Scotty up to 1.4.2.…6.3
- CVE-2026-93537A user who can supply bundle content to a repository referen…6.5
- CVE-2026-93539A vulnerability was discovered in Fleet's Git webhook receiv…5.4
- CVE-2026-9354A vulnerability was detected in NousResearch hermes-agent up…6.5
- CVE-2026-93540A privilege mismatch was found in Fleet. When a bundle reque…6.5
- CVE-2026-93541An out-of-bounds read in libXi's XQueryDeviceState() in libX…6.5
- CVE-2026-93542An out-of-bounds read in libXi's XI2 class parsing via size_…6.5
- CVE-2026-93543An out-of-bounds read in libXi's XI2 class parser in libXi b…7.4
Are you affected by CVE-2026-93538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
