Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-44949

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-306 Ausencia de autenticación para una función crítica
Fecha de publicación:
30/06/2026
Última modificación:
02/07/2026

Descripción

*** Pendiente de traducción *** A Rancher FleetWorkspace admission path allowed side effects to occur in<br /> the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to<br /> the in-cluster rancher-webhook service<br /> could submit a crafted admission payload and cause workspace-related <br /> Kubernetes objects to be created with attacker-chosen identity data.

Referencias a soluciones, herramientas e información