Impact
A privilege mismatch in Rancher Fleet allows a bundle to change namespace labels and annotations without the bundle’s service account having the necessary authorisation. This means an attacker who can deploy or modify a Fleet bundle can alter the metadata of any target namespace, potentially impacting resource categorisation, access controls, and other automation that relies on namespace labels.
Affected Systems
The vulnerability affects SUSE Rancher Fleet versions 0.16.x before 0.16.2, 0.15.x before 0.15.7, 0.14.x before 0.14.11, 0.13.x before 0.13.16, and earlier releases that have not been patched.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating a medium severity impact. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation yet. An attacker would need the ability to deploy or edit a Fleet bundle, a privilege that is usually granted to users with cluster or project-level write access. With that capability, the attacker can set the namespaceLabels or namespaceAnnotations field in the bundle spec to modify the target namespace’s metadata, bypassing the normal authorization check that would normally restrict that action. Therefore, organisations running affected Fleet versions should treat this as a potential privilege escalation vector that could compromise namespace isolation and metadata integrity.
OpenCVE Enrichment