PT-2026-97727 · Suse · Rancher

·

CVE-2026-88804

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rancher (affected versions not specified)
Description An unauthenticated attacker can perform an update of public UI settings to plant malicious content that executes in the browser of users visiting the login page. This stored Cross-Site Scripting (XSS) allows for the leakage of the local administrator bootstrap password or the hijacking of active administrator sessions, potentially granting complete control over the installation and its managed downstream clusters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88804
GHSA-992F-XH8R-JG2F

Affected Products

Rancher