Vulnerability Description
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-44939?
CVE-2026-44939 is a documented vulnerability. A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to ...
How severe is CVE-2026-44939?
CVSS scoring is not yet available for CVE-2026-44939. Check NVD for updates.
Is there a patch for CVE-2026-44939?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.