Sploitus

CVE-2026-44936

No indexed exploits for CVE-2026-44936 yet

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials.

Affected products
Fleet
Suse Rancher Fleet
< 0.12.15, 0.13.11, 0.14.6, 0.15.2
Fix
Available
CVSS 3.1
5.0 MEDIUM
EPSS
0.3% (26th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2026-07-06
Attack patterns
CAPEC-122
CVE-2026-44936 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-44936 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-44936 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.