CVE-2026-44949
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
30/06/2026
Last modified:
02/07/2026
Description
A Rancher FleetWorkspace admission path allowed side effects to occur in<br />
the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to<br />
the in-cluster rancher-webhook service<br />
could submit a crafted admission payload and cause workspace-related <br />
Kubernetes objects to be created with attacker-chosen identity data.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH


