CVE-2026-44948: Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44948?
CVE-2026-44948 has a medium severity score of 5.3 according to CVSS.
How do I fix CVE-2026-44948?
To fix CVE-2026-44948, you should update Rancher Fleet to versions 0.12.17, 0.13.13, 0.14.8, or 0.15.4 or later.
What does CVE-2026-44948 vulnerability entail?
CVE-2026-44948 is a path traversal vulnerability that allows attackers to traverse outside the intended directory in the Rancher Fleet ImageScan subsystem.
Which versions of Rancher are affected by CVE-2026-44948?
Rancher Fleet versions 0.12.0 to 0.12.16, 0.13.0 to 0.13.12, 0.14.0 to 0.14.7, and 0.15.0 to 0.15.3 are affected by CVE-2026-44948.
What could be the impact of exploiting CVE-2026-44948?
Exploiting CVE-2026-44948 could lead to a denial of service by allowing unauthorized file access.