SUSE Linux security advisory (AV26-974)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-974Date: September 29, 2026 As of September 28, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 0.12.19 Prior to 0.13.15 Prior to 0.13.16 Prior to 0.14.10 Prior to 0.14.10 Prior to 0.15.6 Prior to 0.15.7 Prior to 0.16.1 Prior to 0.16.2 Prior to 2.11.18 Prior to 2.12.14 Prior to 2.13.10 Prior to 2.14.6 Prior to 2.15.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher Session Not Revoked Server-Side on Logout in Rancher Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration in Fleet SUSE:Update Advisories | SUSE

This version

Version
1 of 1
Recorded
September 29, 2026 16:00
Change
Initial
Content hash
577e57c7b36a931ff2501ced07d703d1
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.