NONE · 0

CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to ...

Vulnerability Description

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-44939?

CVE-2026-44939 is a documented vulnerability. A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to ...

How severe is CVE-2026-44939?

CVSS scoring is not yet available for CVE-2026-44939. Check NVD for updates.

Is there a patch for CVE-2026-44939?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.