All CVEs
Vulnerability intelligence

CVE-2026-44939

SUSE Rancher CWE-95

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

CVSS Score
9.4
Critical
EPSS — Exploit Probability
1.3%
Riskier than 69% of all CVEs · checked 2026-09-08
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026

Coverage timeline

Related CVEs — SUSE