Tag
#Kubernetes
Rancher Vulnerable to Command Injection via Unsanitized YAML Parameter (CVE-2026-44939)
A critical command injection vulnerability (CVE-2026-44939, CVSS 9.4) has been identified in Rancher Manager's cluster import endpoint. An attacker can exploit this flaw by injecting malicious YAML configurations, potentially achieving full control over downstream Kubernetes clusters. Affected versions of Rancher must be updated to patched releases to mitigate this vulnerability.
Critical Privilege Escalation Vulnerability in Rancher Manager
A critical vulnerability (CVE-2026-41052) with a CVSS score of 9.4 has been identified in Rancher Manager, allowing users with the Project Owner role to escalate privileges to the host level. This vulnerability is exploitable under specific access patterns, enabling attackers to deploy privileged containers, access host-level resources, and potentially compromise the entire cluster. The vulnerability has not been actively exploited but requires immediate attention. Affected versions can be patched by upgrading to Rancher versions v2.12.10, v2.13.6, or v2.14.2.
Understanding the Radius Controller Vulnerability: Preventing Cross-Tenant Resource Deletion
A configuration-validation issue in the Radius Kubernetes controller can cause it to delete a container resource via an injected Deployment annotation. This vulnerability, known as the 'Confused Deputy' pattern, can have significant impacts in multi-tenant installations.