Sceawere

Vulnerability Detail

CVE-2026-93537UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Fleet Arbitrary File Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
SUSE
Product
Rancher
Attack Type
CWE-23 Relative path traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T14:17:23.437Z",
  "pubdate": "2026-09-28T14:17:23.437Z",
  "executiveSummary": "A critical security vulnerability exists in SUSE Rancher Fleet allowing unauthorized local file access. By manipulating bundle content within a Git repository, an authenticated user with Git push access or permissions to modify GitRepo resources can force the Fleet controller to read arbitrary files from the underlying filesystem.\nThe vulnerability involves the unauthorized inclusion of sensitive filesystem data into generated Bundle resources, effectively bypassing Kubernetes RBAC restrictions. This allows attackers to exfiltrate sensitive configuration files, internal system data, or credential material, including Helm registry secrets designated for bundle-processing jobs.\nThis issue impacts Fleet versions 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, and 0.12 before 0.12.20. Successful exploitation grants attackers the ability to escalate their access via credential harvesting, posing a severe risk to the confidentiality and integrity of the managed Kubernetes environment.\nThe attack is performed via the GitRepo interface, requiring the attacker to have enough privileges to define or modify repository configurations that Fleet processes. There is no requirement for direct access to the Fleet controller's node, as the exploitation is triggered via the standard Git repository synchronization flow.",
  "technicalDetails": "The root cause of this vulnerability lies in insufficient input validation and path sanitization within the Fleet bundle-processing engine. When Fleet processes a GitRepo resource, it fetches the contents of the specified repository and initializes a synchronization task. If a user can inject specifically crafted content into the repository bundle, the process fails to enforce strict boundaries on file resolution mechanisms.\nThe vulnerability allows the processing engine to traverse or resolve paths outside of the expected directory structure during the bundle generation phase. When the engine encounters these references, it reads the target file from the node's local filesystem where the controller/job executes and includes the content within the resulting Bundle resource. Because this bundle is stored and observable via the Kubernetes API, an attacker who does not have RBAC privileges to access sensitive files directly can view them once they are serialized into the manifest.\nThe attack flow begins with the attacker modifying the bundle content within a linked Git repository. This might involve utilizing symlinks or path traversal patterns within the configuration that points to sensitive paths, such as /etc/shadow, cloud provider metadata tokens, or specifically, Helm registry credentials cached in the filesystem. Once the repository is updated, the Fleet controller triggers a synchronization loop. The controller executes the processing logic, which inadvertently honors the malicious path references. The sensitive content is read into memory and then embedded into the Bundle object. Finally, the attacker retrieves the Bundle object via standard kubectl commands or other Kubernetes API access, effectively exfiltrating the contents of the unauthorized files.\nA significant implication of this vulnerability is the potential for credential exposure. When per-path Helm credentials are configured, these secrets are often mounted or available to the environment performing the bundle processing. Because the processor blindly consumes and embeds content based on the repository instructions, the attacker can target these credential stores, gaining elevated persistence or access to external container registries that were previously isolated from the attacker’s current Kubernetes identity.\nThis vulnerability is present in the bundle-processing component of Fleet. It does not require network-level access to the internal cluster components, as the entry point is the external Git repository synchronization mechanism, making it highly effective against environments where GitOps workflows are strictly integrated. The vulnerability is mitigated in later releases of the affected branches through improved verification of file paths and restricting the controller's ability to access unauthorized files outside the repository's context."
}
CVE-2026-93537: Fleet Arbitrary File Read Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere