All CVEs
Vulnerability intelligence

CVE-2026-44939

CWE-95

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

CVSS Score
Critical
EPSS — Exploit Probability
1.3%
Riskier than 67% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026

Coverage timeline