---
cve: "CVE-2026-44934"
severity: "HIGH"
cvss: 7.0
epss: "11%"
vendor: "SUSE"
kev: false
exploited: false
published: "2026-07-06 09:16:36"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T00:07:05+02:00"
---

# CVE-2026-44934

> 7.0 HIGH · 🧪 PoC

## Beschreibung

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- 18b27e8ac4b524f332796224f3bb78935ea091f8 (Commit)

## Referenzen

- <https://github.com/rancher/rancher-ai-agent/security/advisories/GHSA-5r2r-h824-fr5v>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-44934) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
