Description
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Published: 2026-09-17
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Revoke the existing service token inside SUSE Observability. Generate a new service token assigned to the `stackstate-guest` role (which enforces read-only access) rather than the default `stackstate-k8s-troubleshooter` role.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.
Title Service token exposure and potential privilege escalation in SUSE Observability
Weaknesses CWE-200
CWE-312
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-17T06:43:19.297Z

Reserved: 2026-05-08T12:29:48.968Z

Link: CVE-2026-44940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T07:16:28.167

Modified: 2026-09-17T07:16:28.167

Link: CVE-2026-44940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-312

    Cleartext Storage of Sensitive Information