Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-88804: Rancher allows anyone to change UI settings and run code

CVE-2026-88804 · published 4 days ago
Summary

In Rancher versions prior to the latest patches, anyone on the internet can modify public interface settings without logging in. This lets attackers insert hidden scripts that run whenever an administrator views the dashboard, potentially stealing data or taking control of the session. Update Rancher to the newest release or apply the provided security patches as soon as possible.

What to do
  • Update suse rancher to version 2.15.2 or later.
Affected software
VendorProductAffected versions
suse rancher < 2.15.2
Original advisory text
Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-88804 · MITRE
Track software like this
Free during beta