OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-88808

HIGH · CVSS 8.8 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability in Rancher Manager allows the Fleet agent to utilize its own cluster-admin credentials to write resources to downstream clusters, bypassing the intended ServiceAccount restrictions. This poses a significant risk in multi-tenancy environments, as it could enable unauthorized access and overwrite configuration files across shared clusters. Organizations using affected versions of SUSE Rancher Fleet, particularly those with multiple teams sharing clusters, should prioritize addressing this issue to mitigate potential security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88808
Severity
HIGH
CVSS
8.8
EPSS
0.27%

Original NVD Description

A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.

Related CVEs

Other vulnerabilities affecting the same vendor(s)