CVE-2026-44949

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/06/2026
Last modified:
02/07/2026

Description

A Rancher FleetWorkspace admission path allowed side effects to occur in<br /> the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to<br /> the in-cluster rancher-webhook service<br /> could submit a crafted admission payload and cause workspace-related <br /> Kubernetes objects to be created with attacker-chosen identity data.