← Back

CVE-2026-41053

nvd nist
Published: Jun 30, 2026Modified: Jul 2, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: meissner@suse.de (Secondary)

Description

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Affected (2)

Products: Suse: Rancher
1 product
Rancher
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Suse
From 2.13.0 to 2.13.6
From 2.14.0 to 2.14.2

References (1)

Source: meissner@suse.de
PatchVendor AdvisoryMitigation

Timeline

No history available yet.