Junglewise Threat Intelligence

CVE-2026-44939: SUSE Rancher command injection in cluster import endpoint

CVE-2026-44939 · Severity: critical · CVSS 9.6 · Published 2026-06-19

Technologies: Suse Rancher Manager, github.com/rancher/rancher (Go), Suse Rancher. Vendors: Suse, Go.

Executive brief

A critical vulnerability in Rancher Manager allows attackers to inject malicious commands into the configuration files used to import new Kubernetes clusters. If an administrator uses a compromised import link, the attacker can gain full administrative control over the entire cluster, including access to sensitive data and the ability to disrupt operations. This occurs because the software fails to properly clean user-provided data before including it in the cluster setup instructions.

Technical details

A command injection vulnerability exists in the Rancher Manager cluster import endpoint `/v3/import/{token}_{clusterId}.yaml`. The `authImage` query parameter is rendered into a Kubernetes manifest template without proper sanitization. By using URL-encoded newlines, an attacker can break out of the `image:` YAML field to inject arbitrary keys, such as `command:`. Exploitation requires the attacker to obtain a valid cluster registration token and trick an administrator into running `kubectl apply` against the malicious URL. Successful exploitation deploys a privileged DaemonSet with `cluster-admin` rights, host network access, and host filesystem mounts on all control-plane nodes. Patches are available in versions 2.14.2, 2.13.6, 2.12.10, 2.11.14, and 2.10.12.

Affected products

  • SUSE Rancher Manager >= 2.14.0, < 2.14.2; >= 2.13.0, < 2.13.6; >= 2.12.0, < 2.12.10; >= 2.11.0, < 2.11.14; >= 2.10.0, < 2.10.12

Timeline

  • 2026-05-27: patched: Fixes committed to Rancher repository
  • 2026-06-19: advisory: NVD publication date
  • 2026-07-01: disclosed: GitHub Advisory published

References

Related threats