Impact
CVE-2026-44939 affects Rancher Manager cluster-import manifest generation in affected Rancher release lines [S1][S2][S3]. Public advisory sources describe command-injection risk when unsafe YAML can be introduced through the authImage parameter in cluster import manifests [S1][S2].
The advisory conditions matter for triage. GitHub and OSV describe exploitation as requiring a valid cluster registration token and a cluster operator applying a maliciously crafted import manifest URL [S1][S2]. If those conditions are met in a deployed vulnerable Rancher environment, the impact can reach downstream Kubernetes cluster control-plane resources [S1][S2].
Root Cause
Affected Rancher Manager releases did not validate the cluster-import authImage value tightly enough before rendering it into generated Kubernetes YAML [S1][S2]. The fix validates that value as an OCI image reference and rejects characters that can break YAML structure [S2][S4].
Affected Versions
Advisory sources list affected Rancher Manager release ranges across maintained branches [S1][S2][S3][S4]:
- Rancher 2.14.x before 2.14.2.
- Rancher 2.13.x before 2.13.6.
- Rancher 2.12.x before 2.12.10.
- Rancher 2.11.x before 2.11.14.
- Rancher 2.10.x before 2.10.12.
How FixVibe covers it
FixVibe's GitHub repo scans flag Rancher Manager Go module metadata and deployment manifests that pin affected release lines, with the file, version or image tag and fixed release.
Fixes and Mitigations
Upgrade Rancher Manager to the fixed release for the active branch: 2.14.2, 2.13.6, 2.12.10, 2.11.14, 2.10.12, or a documented vendor-supported backport [S1][S2][S4]. Update Go module metadata, Helm values, Dockerfiles, Docker Compose files, Kubernetes manifests, GitOps overlays, image mirrors, and CI/deployment images that can keep an affected rancher/rancher runtime in service.
While rollout completes, keep cluster-registration tokens protected, share import URLs only through trusted channels, and apply cluster import manifests only from trusted Rancher origins [S1][S2].
