Full Report
SUSE Linux security advisory (AV26-974)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in SUSE Rancher and Fleet
## CVE Details
*Note: While the advisory highlights specific flaws, the following primary CVEs are associated with the linked disclosures:*
- **CVE ID:** CVE-2026-XXXXX (Associated with GHSA-992f-xh8r-jg2f, GHSA-6vpq-mf48-9794, GHSA-q9v4-358v-r8q5, GHSA-h9p5-fp5h-qpqr)
- **CVSS Score:** Varies (High to Critical based on technical impact)
- **CWE:** CWE-79 (Stored XSS), CWE-613 (Insufficient Session Expiration), CWE-269 (Improper Privilege Management), CWE-200 (Information Exposure)
## Affected Systems
- **Products:** SUSE Rancher and Rancher Fleet
- **Versions:**
- Rancher v2.11.x (prior to 2.11.18)
- Rancher v2.12.x (prior to 2.12.14)
- Rancher v2.13.x (prior to 2.13.10)
- Rancher v2.14.x (prior to 2.14.6)
- Rancher v2.15.x (prior to 2.15.2)
- Fleet (various versions prior to 0.12.19 through 0.16.2)
- **Configurations:** Default installations utilizing UI settings and Fleet agent-initiated registration.
## Vulnerability Description
Multiple vulnerabilities have been identified in the Rancher ecosystem:
1. **Stored XSS via Public UI Settings:** Allows unauthenticated updates to public UI settings, enabling the injection of malicious scripts into the Rancher dashboard.
2. **Session Revocation Flaw:** Sessions are not properly revoked server-side upon logout, potentially allowing hijacked sessions to remain valid.
3. **Fleet Agent Privilege Escalation:** The Fleet agent copies downstream resources using `cluster-admin` privileges, which can be abused to perform cross-namespace writes on downstream clusters.
4. **Cross-tenant Disclosure:** Spoofed cluster labels during agent-initiated registration in Fleet can lead to the disclosure of `BundleDeployment` and `Secret` information across tenants.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; PoC details are available in referenced GitHub Security Advisories.
- **Complexity:** Low to Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Secret disclosure and session hijacking)
- **Integrity:** High (Cross-namespace writes and UI manipulation)
- **Availability:** Medium
## Remediation
### Patches
Users should upgrade to the following versions or newer:
- **Rancher:** 2.11.18, 2.12.14, 2.13.10, 2.14.6, 2.15.2
- **Fleet:** 0.12.19, 0.13.15, 0.13.16, 0.14.10, 0.15.6, 0.15.7, 0.16.1, 0.16.2
### Workarounds
- **XSS/UI Settings:** Restrict network access to the Rancher API and ensure strict egress filtering.
- **Session Revocation:** Implement short session timeouts and force re-authentication via OIDC/SAML providers where possible.
- **Fleet:** Limit the use of agent-initiated registration and audit cluster labels for downstream clusters.
## Detection
- **Indicators of Compromise:** Unusual modifications to public UI settings (e.g., logos, banners, or scripts); unauthorized cross-namespace resource creation in downstream clusters.
- **Detection methods:** Audit Rancher API logs for unauthenticated `PUT/POST` requests to settings endpoints. Monitor Kubernetes audit logs for `cluster-admin` actions performed by the Fleet agent service account that cross namespace boundaries.
## References
- **Vendor Advisories:**
- hxxps[://]www[.]suse[.]com/support/update/
- hxxps[://]github[.]com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
- hxxps[://]github[.]com/rancher/rancher/security/advisories/GHSA-6vpq-mf48-9794
- hxxps[://]github[.]com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5
- hxxps[://]github[.]com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr
- **Official Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/suse-linux-security-advisory-av26-974