PT-2026-85055 · Suse · Rancher

·

CVE-2026-71403

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's username and principalIds fields. A user holding the update verb on users.management.cattle.io could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings.
This issue affects Rancher: before 2.15.1.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71403

Affected Products

Rancher