FixVibe

critical

Rancher Command Injection via Unsanitized YAML Parameter (CVE-2026-44939)

CVE-2026-44939 affects Rancher Manager cluster-import manifest generation in affected Rancher release lines. FixVibe now covers it as a GitHub repo version-based advisory when authorized repository evidence shows affected Rancher Manager Go module or deployment image versions. Upgrade Rancher Manager to the fixed release for the branch in use and protect cluster-registration tokens.

CVE-2026-44939GHSA-mhc6-2gfq-xx62GO-2026-5875CWE-95

Impact

CVE-2026-44939 affects Rancher Manager cluster-import manifest generation in affected Rancher release lines [S1][S2][S3]. Public advisory sources describe command-injection risk when unsafe YAML can be introduced through the authImage parameter in cluster import manifests [S1][S2].

The advisory conditions matter for triage. GitHub and OSV describe exploitation as requiring a valid cluster registration token and a cluster operator applying a maliciously crafted import manifest URL [S1][S2]. If those conditions are met in a deployed vulnerable Rancher environment, the impact can reach downstream Kubernetes cluster control-plane resources [S1][S2].

Root Cause

Affected Rancher Manager releases did not validate the cluster-import authImage value tightly enough before rendering it into generated Kubernetes YAML [S1][S2]. The fix validates that value as an OCI image reference and rejects characters that can break YAML structure [S2][S4].

Affected Versions

Advisory sources list affected Rancher Manager release ranges across maintained branches [S1][S2][S3][S4]:

  • Rancher 2.14.x before 2.14.2.
  • Rancher 2.13.x before 2.13.6.
  • Rancher 2.12.x before 2.12.10.
  • Rancher 2.11.x before 2.11.14.
  • Rancher 2.10.x before 2.10.12.

How FixVibe covers it

FixVibe's GitHub repo scans flag Rancher Manager Go module metadata and deployment manifests that pin affected release lines, with the file, version or image tag and fixed release.

Fixes and Mitigations

Upgrade Rancher Manager to the fixed release for the active branch: 2.14.2, 2.13.6, 2.12.10, 2.11.14, 2.10.12, or a documented vendor-supported backport [S1][S2][S4]. Update Go module metadata, Helm values, Dockerfiles, Docker Compose files, Kubernetes manifests, GitOps overlays, image mirrors, and CI/deployment images that can keep an affected rancher/rancher runtime in service.

While rollout completes, keep cluster-registration tokens protected, share import URLs only through trusted channels, and apply cluster import manifests only from trusted Rancher origins [S1][S2].