CVE-2026-93540: Fleet applies namespace labels and annotations without the bundle's service account privileges

Published Sep 28, 2026
·
Updated

A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata update was not subject to the same authorization as the rest of the bundle's deployment. As a result, a bundle could change labels and annotations on a target namespace even when the identity it was pinned to was not authorized to modify that namespace.

This affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, 0.13 before 0.13.16 and potentially older versions.

Affected Software

1 affected component
SUSE Fleet>=0.16<0.16.2, >=0.15<0.15.7, >=0.14<0.14.11, >=0.13<0.13.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.16.2
  2. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.15.7
  3. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.14.11
  4. Upgrade

    Upgrade SUSE Rancher Fleet to a version that resolves this vulnerability.

    Fixed in 0.13.16

Event History

Sep 28, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Affected releases are SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, 0.14 before 0.14.11, and 0.13 before 0.13.16. Potentially older versions may also be affected.

2

What must an attacker be able to do to exploit this?

An attacker needs privileges to deploy or control a bundle that uses the namespaceLabels or namespaceAnnotations options. The bundle can then update metadata on its target namespace despite the pinned service account lacking authorization to modify that namespace.

3

Are bundles that do not request namespace metadata changes affected?

The reported authorization mismatch applies specifically to namespace labels and annotations requested through namespaceLabels and namespaceAnnotations. The provided information does not indicate that other bundle deployment operations bypass the pinned service account's authorization.

4

How can I identify possible exploitation or exposure?

Review bundles using namespaceLabels or namespaceAnnotations, especially where their pinned service accounts do not have permission to update the target namespaces. Review namespace label and annotation changes associated with those bundles for unexpected metadata updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203