Junglewise Threat Intelligence

CVE-2026-44949: SUSE Rancher Webhook RBAC injection in FleetWorkspace

CVE-2026-44949 · Severity: info · CVSS 7 · Published 2026-06-30

Vendors: Suse.

Executive brief

A vulnerability in the Rancher Webhook component could allow an attacker already inside a Kubernetes cluster to create unauthorized workspace objects. By sending a specially crafted request to the internal webhook service, an attacker can manipulate identity data and gain unauthorized control over workspace permissions. This could lead to a breach of security boundaries between different teams or projects managed within the same Rancher environment.

Technical details

A vulnerability in the Rancher FleetWorkspace mutating webhook allows side effects to occur during the admission path. An attacker with network access to the in-cluster rancher-webhook service (typically requiring an existing foothold in a pod) can submit a crafted admission payload. This results in the creation of workspace-related Kubernetes objects with attacker-controlled identity data, leading to RBAC injection and unauthorized integrity changes. The issue is rooted in missing authentication for a critical function (CWE-306) within the webhook handler. Patches move object generation to the authenticated Rancher provisioning controller path.

Affected products

  • SUSE Rancher Webhook >=0.7.0, <0.7.10; >=0.8.0, <0.8.7; >=0.9.0, <0.9.6; >=0.10.0, <0.10.7

Timeline

  • 2026-06-29: advisory: GitHub Advisory GHSA-h83p-cq95-vph4 published
  • 2026-06-30: disclosed: NVD publication date

References