Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN947 _____________________________________________________________________ DATE : 29/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running rancher/fleet (Go) versions prior to 0.16.2, 0.15.7, 0.14.11, 0.13.16, 0.12.20, Rancher versions prior to 2.15.2, 2.14.6, 2.13.10, v2.12.14, and v2.11.18. ===================================================================== https://github.com/rancher/fleet/security/advisories/GHSA-q9v4-358v-r8q5 https://github.com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr https://github.com/rancher/fleet/security/advisories/GHSA-wpfm-r97v-3j4h https://github.com/rancher/fleet/security/advisories/GHSA-m93g-8438-2cgg https://github.com/rancher/fleet/security/advisories/GHSA-8vfv-33cg-g75q _____________________________________________________________________ Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters Critical pdellamore published GHSA-q9v4-358v-r8q5 Package github.com/rancher/fleet (Go) Affected versions >=v0.16.0, =v0.15.0, =v0.14.0, =v0.16.0, =v0.15.0, =v0.14.0, =v0.13.0, =v0.12.0, =v0.16.0, =v0.15.0, =v0.14.0, =v0.13.0, =v0.12.0, =v0.16.0, =v0.15.0, =v0.14.0, =v0.13.0, : References rancher/fleet#5351 (main) rancher/fleet#5415 (release/v0.16) rancher/fleet#5657 (release/v0.15) rancher/fleet#5662 (release/v0.14) rancher/fleet#5663 (release/v0.13) CWE-269: Improper Privilege Management CWE-863: Incorrect Authorization For more information If you have any questions or comments about this advisory: Reach out to the SUSE Rancher Security team for security related inquiries. Open an issue in the Rancher repository. Verify our support matrix and product support life cycle. Severity High 7.1/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity Low Attack Requirements None Privileges Required Low User interaction None Vulnerable System Impact Metrics Confidentiality None Integrity High Availability None Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVE ID CVE-2026-93540 Weaknesses Weakness CWE-269 Weakness CWE-863 Credits @manus-use manus-use Finder _____________________________________________________________________ Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver Moderate pdellamore published GHSA-8vfv-33cg-g75q Package github.com/rancher/fleet Affected versions >=v0.16.0,