CVE-2026-93538: Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet

Published Sep 28, 2026
·
Updated

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster. This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

Affected Software

1 affected component
SUSE Rancher Fleet>=0.16<0.16.1, >=0.15<0.15.6, >=0.14<0.14.10, >=0.13<0.13.15, >=0.12<0.12.19, <0.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.16.1
  2. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.15.6
  3. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.14.10
  4. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.13.15
  5. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.12.19

Event History

Sep 28, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed to cross-tenant impact?

The issue applies where multiple tenants can register clusters into the same Fleet workspace namespace. A tenant's cluster can then match GitRepo or Bundle targeting rules intended for another cluster.

2

What access does an attacker need?

An attacker needs the ability to register a cluster into a Fleet workspace namespace shared with other tenants. They can supply cluster labels during agent-initiated registration, including labels in the reserved management.cattle.io/ namespace.

3

Which Fleet releases contain fixes?

Fixed releases are Fleet 0.16.1, 0.15.6, 0.14.10, 0.13.15, and 0.12.19. Versions earlier than those patch levels, including older versions, are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203