SUSE Linux security advisory (AV26-974)
Canadian Cyber Centre relayed SUSE advisory AV26-974 covering Rancher flaws including stored XSS, session issues, and cross-tenant secret disclosure; patches advised.
The Canadian Centre for Cyber Security issued advisory AV26-974 for SUSE Rancher vulnerabilities affecting numerous versions across release lines up to 2.15.2. The flaws include unauthenticated update of public UI settings leading to stored cross-site scripting, sessions not revoked server-side on logout, Fleet agent copying downstream resources with cluster-admin privileges allowing cross-namespace writes, and cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration. Users and administrators are urged to apply updates as they become available.
- Multiple Rancher versions affected across release lines through 2.15.2
- Stored XSS via unauthenticated update of public UI settings
- Fleet agent can perform cross-namespace writes with cluster-admin privileges
- Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels
Full article139 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-974
Date: September 29, 2026
As of September 28, 2026, SUSE is affected by vulnerabilities in the following product:
- Rancher
- Prior to 0.12.19
- Prior to 0.13.15
- Prior to 0.13.16
- Prior to 0.14.10
- Prior to 0.14.10
- Prior to 0.15.6
- Prior to 0.15.7
- Prior to 0.16.1
- Prior to 0.16.2
- Prior to 2.11.18
- Prior to 2.12.14
- Prior to 2.13.10
- Prior to 2.14.6
- Prior to 2.15.2
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
- Session Not Revoked Server-Side on Logout in Rancher
- Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters
- Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet
- SUSE:Update Advisories | SUSE
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-974