---
cve: "CVE-2026-93538"
severity: "HIGH"
cvss: 7.1
epss: "0.2%"
vendor: "SUSE"
kev: false
exploited: false
published: "2026-09-28 15:17:24"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T15:31:22+02:00"
---

# CVE-2026-93538

> 7.1 HIGH · 🧪 PoC

## Beschreibung

A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster labels, a party able to register a cluster into a Fleet workspace namespace shared with other tenants could cause its own cluster to satisfy targeting rules that administrators intended for a different cluster.
This affects SUSE Rancher Fleet 0.16 before 0.16.1, 0.15 before 0.15.6, 0.14 before 0.14.10, 0.13 before 0.13.15, 0.12 before 0.12.19 and older versions.

## CNA-Record (Kanon, cvelistV5)

- CNA: **suse**
- State: PUBLISHED
- Stand: 2026-09-28 16:22:26
- CNA-CVSS: **7.1** (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-290** — Authentication Bypass by Spoofing
  This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
- **CWE-639** — Authorization Bypass Through User-Controlled Key
  The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

## Angriffsmuster (CAPEC)

- [CAPEC-21 — Exploitation of Trusted Identifiers](https://capec.mitre.org/data/definitions/21.html) _(Severity: High)_
- [CAPEC-22 — Exploiting Trust in Client](https://capec.mitre.org/data/definitions/22.html) _(Severity: High)_
- [CAPEC-59 — Session Credential Falsification through Prediction](https://capec.mitre.org/data/definitions/59.html) _(Severity: High)_
- [CAPEC-60 — Reusing Session IDs (aka Session Replay)](https://capec.mitre.org/data/definitions/60.html) _(Severity: High)_
- [CAPEC-459 — Creating a Rogue Certification Authority Certificate](https://capec.mitre.org/data/definitions/459.html) _(Severity: Very High)_
- [CAPEC-461 — Web Services API Signature Forgery Leveraging Hash Function Extension Weakness](https://capec.mitre.org/data/definitions/461.html) _(Severity: High)_
- [CAPEC-473 — Signature Spoof](https://capec.mitre.org/data/definitions/473.html)
- [CAPEC-476 — Signature Spoofing by Misrepresentation](https://capec.mitre.org/data/definitions/476.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1134 — Access Token Manipulation](https://attack.mitre.org/techniques/T1134/)
- [T1528 — Steal Application Access Token](https://attack.mitre.org/techniques/T1528/)
- [T1539 — Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539/)
- [T1134.001 — Access Token Manipulation:Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001/)
- [T1550.004 — Use Alternate Authentication Material:Web Session Cookie](https://attack.mitre.org/techniques/T1550/004/)
- [T1036.001 — Masquerading: Invalid Code Signature](https://attack.mitre.org/techniques/T1036/001/)
- [T1553.002 — Subvert Trust Controls: Code Signing](https://attack.mitre.org/techniques/T1553/002/)

## Patch verfügbar (OSV)

- 3d1766d5b737501e0386d25558ebc87da867f77a (Commit)
- bde240cf8eb3122dd2a7e65849e8e30e74d1bdff (Commit)

## BSI-Hinweise (deutsch)

- [Fleet: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3546) — _BSI-Einstufung: hoch_
  Ein Angreifer kann mehrere Schwachstellen in Fleet ausnutzen, um erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand auszulösen.

## Referenzen

- <https://github.com/rancher/fleet/security/advisories/GHSA-h9p5-fp5h-qpqr>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-93538/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
