Suse · Rancher · CVE-2026-41053
**Name of the Vulnerable Software and Affected Versions**
Rancher versions 2.13.0 through 2.13.5
Rancher versions 2.14.0 through 2.14.1
**Description**
Incorrect authentication caching in the GitHub authentication provider occurs during team membership expansion, causing cached principals to be reused across different users. This issue stems from improper cache scoping and validation, which leads to the mixing or incorrect reuse of identity and team resolution results. A logged-in user can trigger authentication flows that rely on the poisoned cache to be granted the access rights of another principal without possessing the required GitHub team membership. This can result in unauthorized access to resources and clusters, enabling privilege escalation, configuration tampering, and potential data exposure.
**Recommendations**
Upgrade Rancher versions 2.13.0 through 2.13.5 to version 2.13.6.
Upgrade Rancher versions 2.14.0 through 2.14.1 to version 2.14.2.