Impact
A Rancher FleetWorkspace admission path contains a flaw that lets an unauthenticated attacker, who can reach the in‑cluster rancher-webhook service, send a crafted admission request. The webhook will create workspace‑related Kubernetes objects using the attacker‑chosen identity data, providing a pathway for privilege escalation through arbitrary RBAC objects.
Affected Systems
This issue affects the Rancher fleet‑workspace mutating webhook in Rancher versions 0.7.0 through 0.10.7, inclusive. The product is offered by SUSE under the Rancher brand. All releases within the specified ranges are vulnerable.
Risk and Exploitability
The CVSS score of 7 classifies the vulnerability as high. Since the EPSS score is not provided and it is not listed in CISA KEV, the public exploitation landscape is uncertain, but the attack vector is clear: unauthenticated network access to the webhook service. If exploited, an attacker could create malicious namespaces and RBAC objects, potentially gaining elevated privileges across the cluster.
OpenCVE Enrichment