A Rancher FleetWorkspace admission path allowed side effects to occur in
the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to
the in-cluster rancher-webhook service
could submit a crafted admission payload and cause workspace-related
Kubernetes objects to be created with attacker-chosen identity data.
CVSS
No CVSS.
References
Configurations
No configuration.
History
30 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 15:16
Updated : 2026-07-02 17:45
NVD link : CVE-2026-44949
Mitre link : CVE-2026-44949
CVE.ORG link : CVE-2026-44949
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
