← Back to CVE List
CVE-2026-44937NVD
Vulnerability Summary
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
CVSS v4.0 Base Metrics — Score 8.3 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- SUSE Rancher >= 0.15.0 and < 0.15.2
- SUSE Rancher >= 0.14.0 and < 0.14.6
- SUSE Rancher >= 0.13.0 and < 0.13.11
- SUSE Rancher >= 0.12.0 and < 0.12.15
- SUSE Rancher 0.15.2
- SUSE Rancher 0.14.6
- SUSE Rancher 0.13.11
- SUSE Rancher 0.12.15