CVE-2026-44934
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
- EPSS probability
- 0.15%
- CWE
- CWE-215
- Published
- 2026-07-06
- Last modified
- 2026-07-06
Affected products
- SUSE Rancher
Weakness type
Related vulnerabilities
- CVE-2026-79694 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-62652 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware...
- CVE-2026-21759 — HCL Hive is affected by an information exposure vulnerability
- CVE-2026-74799 — SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure
- CVE-2026-40173 — Dgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-33247 — NATS credentials are exposed in monitoring port via command-line argv
- CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
- CVE-2025-12616 — PHPGurukul News Portal settings.py insertion of sensitive information into debugging code