Executive brief
A vulnerability in the Rancher Webhook component could allow an attacker already inside a Kubernetes cluster to create unauthorized workspace objects. By sending a specially crafted request to the internal webhook service, an attacker can manipulate identity data and gain unauthorized control over workspace permissions. This could lead to a breach of security boundaries between different teams or projects managed within the same Rancher environment.
Technical details
A vulnerability in the Rancher FleetWorkspace mutating webhook allows side effects to occur during the admission path. An attacker with network access to the in-cluster rancher-webhook service (typically requiring an existing foothold in a pod) can submit a crafted admission payload. This results in the creation of workspace-related Kubernetes objects with attacker-controlled identity data, leading to RBAC injection and unauthorized integrity changes. The issue is rooted in missing authentication for a critical function (CWE-306) within the webhook handler. Patches move object generation to the authenticated Rancher provisioning controller path.
Affected products
- SUSE Rancher Webhook >=0.7.0, <0.7.10; >=0.8.0, <0.8.7; >=0.9.0, <0.9.6; >=0.10.0, <0.10.7
Timeline
- 2026-06-29: advisory: GitHub Advisory GHSA-h83p-cq95-vph4 published
- 2026-06-30: disclosed: NVD publication date