CVE-2026-93537: Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle directory

Published Sep 28, 2026
·
Updated

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include their contents in the generated Bundle resource. This can expose configuration or credential material that the user has no Kubernetes RBAC permission to read, including Helm registry credentials made available to the bundle-processing job when per-path Helm credentials are configured. This affects Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16, 0.12 before 0.12.20 and potentially older unsupported versions.

Affected Software

1 affected component
SUSE Rancher Fleet>=0.16<0.16.2, >=0.15<0.15.7, >=0.14<0.14.11, >=0.13<0.13.16, >=0.12<0.12.20

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.16.2
  2. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.15.7
  3. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.14.11
  4. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.13.16
  5. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.12.20

Event History

Sep 28, 2026
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs Git push access to a repository referenced by a GitRepo resource, or permission to create or modify a GitRepo. It is not described as exploitable by an unauthenticated user with no repository or GitRepo control.

2

What data could be exposed?

The issue can cause the bundle-processing environment to read files outside the bundle directory and place their contents in a generated Bundle resource. Exposed material may include configuration or credentials that the attacker cannot otherwise read through Kubernetes RBAC, including Helm registry credentials when per-path Helm credentials are configured.

3

Which Fleet versions need remediation?

Upgrade to Fleet 0.16.2 or later, 0.15.7 or later, 0.14.11 or later, 0.13.16 or later, or 0.12.20 or later, depending on the supported release line in use. Older unsupported versions may also be affected.

4

What can be done before upgrading?

Restrict who can push bundle content to repositories referenced by GitRepo resources and who can create or modify GitRepo resources. Pay particular attention to environments using per-path Helm credentials, since those credentials can be available to the bundle-processing job.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203