Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-88804: Rancher allows anyone to change UI settings and run code
CVE-2026-88804 · published 4 days ago
Summary
In Rancher versions prior to the latest patches, anyone on the internet can modify public interface settings without logging in. This lets attackers insert hidden scripts that run whenever an administrator views the dashboard, potentially stealing data or taking control of the session. Update Rancher to the newest release or apply the provided security patches as soon as possible.
What to do
- Update suse rancher to version 2.15.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| suse | rancher | < 2.15.2 |
Original advisory text
Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
References
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta