CVE-2026-44939 PUBLISHED

Command injection through unsanitized YAML parameter in Rancher

Assigner: suse
Reserved: 08.05.2026 Published: 19.06.2026 Updated: 19.06.2026

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor SUSE
Product Rancher
Versions Default: unaffected
  • affected from 2.14.0 to 2.14.2 (excl.)
  • affected from 2.13.0 to 2.13.6 (excl.)
  • affected from 2.12.0 to 2.12.10 (excl.)
  • affected from 2.11.0 to 2.11.14 (excl.)
  • affected from 2.10.0 to 2.10.12 (excl.)

References

Problem Types

  • CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection') CWE

Impacts

  • CAPEC-242 Code Injection