CVE-2026-44948 PUBLISHED

Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler

Assigner: suse
Reserved: 08.05.2026 Published: 30.06.2026 Updated: 30.06.2026

A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor SUSE
Product Rancher
Versions Default: unaffected
  • affected from 0.12.0 to 0.12.16 (excl.)
  • affected from 0.13.0 to 0.13.12 (excl.)
  • affected from 0.14.0 to 0.14.7 (excl.)
  • affected from 0.15.0 to 0.15.3 (excl.)

Credits

  • Sergey Kanibor finder

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-126 Path Traversal