# CVE-2026-44935

## Summary

- **CVE ID:** CVE-2026-44935
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1287
- **Published:** Jul 2, 2026
- **Last Modified:** Jul 3, 2026

## Description

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

## Affected Products

- SUSE — Rancher (0.15.0)
- SUSE — Rancher (0.14.0)
- SUSE — Rancher (0.13.0)
- SUSE — Rancher (0.12.0)

## References

- [CNA](https://github.com/rancher/fleet/security/advisories/GHSA-xr65-5cpm-g36x)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.49%
- **EPSS Percentile:** 40.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._