Unrated severityNVD Advisory· Published Jun 19, 2026
Command injection through unsanitized YAML parameter in Rancher
CVE-2026-44939
Description
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.14.2
Patches
Vulnerability mechanics
References
1- github.com/rancher/rancher/security/advisories/GHSA-mhc6-2gfq-xx62mitrevendor-advisory
News mentions
0No linked articles in our index yet.