PT-2026-97727 · Suse · Rancher
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rancher (affected versions not specified)
Description
An unauthenticated attacker can perform an update of public UI settings to plant malicious content that executes in the browser of users visiting the login page. This stored Cross-Site Scripting (XSS) allows for the leakage of the local administrator bootstrap password or the hijacking of active administrator sessions, potentially granting complete control over the installation and its managed downstream clusters.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rancher