CVE-2026-88808 is a vulnerability in Suse Rancher
Published on September 28, 2026
Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files.
This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
Vulnerability Analysis
CVE-2026-88808 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Execution with Unnecessary Privileges
The software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Products Associated with CVE-2026-88808
Want to know whenever a new CVE is published for Suse Rancher? stack.watch will email you.
Affected Versions
SUSE Rancher:- Version 0.16.0 and below 0.16.2 is affected.
- Version 0.15.0 and below 0.15.7 is affected.
- Version 0.14.0 and below 0.14.11 is affected.