Description
A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.

This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.
Published: 2026-09-28
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A privilege mismatch in Rancher Fleet allows a bundle to change namespace labels and annotations without the bundle’s service account having the necessary authorisation. This means an attacker who can deploy or modify a Fleet bundle can alter the metadata of any target namespace, potentially impacting resource categorisation, access controls, and other automation that relies on namespace labels.

Affected Systems

The vulnerability affects SUSE Rancher Fleet versions 0.16.x before 0.16.2, 0.15.x before 0.15.7, 0.14.x before 0.14.11, 0.13.x before 0.13.16, and earlier releases that have not been patched.

Risk and Exploitability

The flaw has a CVSS score of 6.5, indicating a medium severity impact. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation yet. An attacker would need the ability to deploy or edit a Fleet bundle, a privilege that is usually granted to users with cluster or project-level write access. With that capability, the attacker can set the namespaceLabels or namespaceAnnotations field in the bundle spec to modify the target namespace’s metadata, bypassing the normal authorization check that would normally restrict that action. Therefore, organisations running affected Fleet versions should treat this as a potential privilege escalation vector that could compromise namespace isolation and metadata integrity.

Generated by OpenCVE AI on September 28, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rancher Fleet to a version that includes the fix (0.16.2 or newer, or 0.15.7/0.14.11/0.13.16 depending on your current release).
  • Reconfigure Fleet to restrict or disable the use of namespaceLabels and namespaceAnnotations in bundles, ensuring that only authorised service accounts can modify namespace metadata.
  • Audit existing bundles for unintended namespace metadata changes and remove or correct any that could alter namespace labels or annotations beyond their intended scope.

Generated by OpenCVE AI on September 28, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace. This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.
Title Fleet applies namespace labels and annotations without the bundle's service account privileges
First Time appeared Suse
Suse rancher
Weaknesses CWE-266
CPEs cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
Vendors & Products Suse
Suse rancher
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-09-28T16:22:25.780Z

Reserved: 2026-09-18T09:08:10.294Z

Link: CVE-2026-93540

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:14.125Z

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:25.220

Modified: 2026-09-28T17:17:52.917

Link: CVE-2026-93540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:45:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment