A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 13:16
Updated : 2026-06-24 05:17
NVD link : CVE-2026-44939
Mitre link : CVE-2026-44939
CVE.ORG link : CVE-2026-44939
JSON object : View
Products Affected
No product.
CWE
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
