Description
A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured.
This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
Published: 2026-09-28
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure via Path Traversal
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw in the valuesFiles handling of SUSE Rancher Fleet’s helm deployment, which can be exploited by a user who can supply or modify bundle content. By referencing files that exist outside the intended bundle directory, the attacker can cause Fleet to read arbitrary files from the environment’s filesystem and embed their contents into the generated Bundle resource. The data exposed can include sensitive configuration data or credential material that the attacker otherwise has no permission to read through Kubernetes RBAC, such as Helm registry credentials supplied to the bundle job.

Affected Systems

Affected versions of SUSE Rancher Fleet include 0.16 versions earlier than 0.16.2, 0.15 earlier than 0.15.7, 0.14 earlier than 0.14.11, 0.13 earlier than 0.13.16, 0.12 earlier than 0.12.20, and potentially older unsupported releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and the attack can be performed when an attacker has push access to the Git repository that feeds bundle content or permission to create or modify a GitRepo resource. Exploitation requires the attacker to supply a specially crafted valuesFiles path that points to an out-of-bundle file; the Fleet bundle-processing job then reads the file from the host filesystem. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation is not yet documented but the threat remains present.

Generated by OpenCVE AI on September 28, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SUSE Rancher Fleet to the first supported release of each affected branch (0.16.2 or newer, 0.15.7 or newer, 0.14.11 or newer, 0.13.16 or newer, 0.12.20 or newer).
  • Restrict write access to the Git repositories used for bundle content so that only trusted users can push changes or create/modify GitRepo resources.
  • If an upgrade is not immediately possible, block the use of valuesFiles that reference local paths by enforcing path restrictions or by disabling per-path Helm credentials for bundle processing.

Generated by OpenCVE AI on September 28, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.
Title Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory
First Time appeared Suse
Suse rancher
Weaknesses CWE-23
CPEs cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
Vendors & Products Suse
Suse rancher
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T17:54:22.754Z

Reserved: 2026-09-18T09:08:10.294Z

Link: CVE-2026-93537

cve-icon Vulnrichment

Updated: 2026-09-28T17:54:12.343Z

cve-icon NVD

Status : Received

Published: 2026-09-28T14:17:23.437

Modified: 2026-09-28T18:17:26.740

Link: CVE-2026-93537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:30:03Z

Weaknesses
  • CWE-23

    Relative Path Traversal