PT-2026-53850 · Suse · Rancher

·

CVE-2026-41053

·

Published

2026-05-28

·

Updated

2026-07-30

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rancher versions 2.13.0 through 2.13.5 Rancher versions 2.14.0 through 2.14.1
Description Incorrect authentication caching in the GitHub authentication provider occurs during team membership expansion, causing cached principals to be reused across different users. This issue stems from improper cache scoping and validation, which leads to the mixing or incorrect reuse of identity and team resolution results. A logged-in user can trigger authentication flows that rely on the poisoned cache to be granted the access rights of another principal without possessing the required GitHub team membership. This can result in unauthorized access to resources and clusters, enabling privilege escalation, configuration tampering, and potential data exposure.
Recommendations Upgrade Rancher versions 2.13.0 through 2.13.5 to version 2.13.6. Upgrade Rancher versions 2.14.0 through 2.14.1 to version 2.14.2.

Exploit

Fix

DoS

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09231
CVE-2026-41053
GHSA-4J6X-2764-M8GH
GO-2026-5869
OPENSUSE-SU-2026:21483-1

Affected Products

Rancher