Critical severityNVD Advisory· Published Jun 19, 2026· Updated Jun 24, 2026
CVE-2026-44939
CVE-2026-44939
Description
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.14.0, < 2.14.2 | 2.14.2 |
github.com/rancher/rancherGo | >= 2.13.0, < 2.13.6 | 2.13.6 |
github.com/rancher/rancherGo | >= 2.12.0, < 2.12.10 | 2.12.10 |
github.com/rancher/rancherGo | >= 2.11.0, < 2.11.14 | 2.11.14 |
github.com/rancher/rancherGo | >= 2.10.0, < 2.10.12 | 2.10.12 |
github.com/rancher/rancherGo | < 0.0.0-20260617231817-2aa77eb283e7 | 0.0.0-20260617231817-2aa77eb283e7 |
Affected products
4- osv-coords3 versionspkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fips-webhookpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.8.1-r32+ 2 more
- (no CPE)range: < 1.8.1-r32
- (no CPE)range: < 1.8.1-r28
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.