Command Injection in Rancher Manager < 2.14.2 Import Endpoint (YAML)
CVE-2026-44939 Published on June 19, 2026

Command injection through unsanitized YAML parameter in Rancher
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

Vendor Advisory NVD

Weakness Type

What is an Eval Injection Vulnerability?

The software receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval"). This may allow an attacker to execute arbitrary code, or at least modify what code can be executed.

CVE-2026-44939 has been classified to as an Eval Injection vulnerability or weakness.


Products Associated with CVE-2026-44939

Want to know whenever a new CVE is published for Suse Rancher? stack.watch will email you.

 

Affected Versions

SUSE Rancher: