---
schema: 1
kind: vulnerability
title: "CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053) — SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership"
headline: "CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053) — SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App"
summary: "SUSE Rancher patched three vulnerabilities on 2026-05-27. CVE-2026-44939 (CVSS 9.6, GHSA-mhc6-2gfq-xx62) is a command injection in the cluster-import endpoint /v3/import/{token}_{clusterId}.yaml: the authImage query parameter is not sanitised, so URL-encoded newlines (%0A) break out of the YAML image: field …"
discovered_at: "2026-05-29T05:00:07Z"
event_date: null
run_id: 2026-05-29-c7f56b00
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - priv-esc
  - patch-available
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - technology
entities: []
cves:
  - id: CVE-2026-44939
    cvss: "9.6"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-41052
    cvss: "8.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-41053
    cvss: "8.8"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://github.com/rancher/rancher/security/advisories/GHSA-mhc6-2gfq-xx62"
    publisher: SUSE Rancher GHSA-mhc6-2gfq-xx62
    role: primary
  - url: "https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744"
    publisher: GHSA-vx8h-4prv-g744
    role: corroborating
  - url: "https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh"
    publisher: GHSA-4j6x-2764-m8gh
    role: corroborating
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1716"
    publisher: BSI WID-SEC-2026-1716
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-29.md
---

SUSE Rancher patched three vulnerabilities on 2026-05-27. [`CVE-2026-44939` (CVSS 9.6, GHSA-mhc6-2gfq-xx62)](https://github.com/rancher/rancher/security/advisories/GHSA-mhc6-2gfq-xx62) is a command injection in the cluster-import endpoint `/v3/import/{token}_{clusterId}.yaml`: the `authImage` query parameter is not sanitised, so URL-encoded newlines (`%0A`) break out of the YAML `image:` field and inject arbitrary YAML keys into the cluster-import manifest. When an admin runs `kubectl apply` against the malicious manifest, attacker-controlled commands run on control-plane nodes through a deployed DaemonSet with elevated privileges. Affected: 2.10.0–2.10.11, 2.11.0–2.11.13, 2.12.0–2.12.9, 2.13.0–2.13.5, 2.14.0–2.14.1. [`CVE-2026-41052` (CVSS 8.4, GHSA-vx8h-4prv-g744)](https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744) lets `project-owner` users flip namespace Pod Security Admission labels to *privileged*, enabling container-to-host escape. [`CVE-2026-41053` (CVSS 8.8, GHSA-4j6x-2764-m8gh)](https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh) is an authorization bug in the GitHub-App auth provider that grants `group principals` for **every** GitHub-org team to any user who belongs to at least one team. [BSI advisory WID-SEC-2026-1716](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1716) carries the German-CERT corroboration. Fixed in 2.10.12 / 2.11.14 / 2.12.10 / 2.13.6 / 2.14.2.
