Suse · Rancher · CVE-2026-88804
**Name of the Vulnerable Software and Affected Versions**
Rancher (affected versions not specified)
**Description**
An unauthenticated attacker can perform an update of public UI settings to plant malicious content that executes in the browser of users visiting the login page. This stored Cross-Site Scripting (XSS) allows for the leakage of the local administrator bootstrap password or the hijacking of active administrator sessions, potentially granting complete control over the installation and its managed downstream clusters.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.