CVE-2026-41052

EUVD-2026-40130
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
suseCNA
9.4 CRITICAL
NETWORK
LOW
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
suserancher
2.12.0 ≤
𝑥
< 2.12.10
CNA
suserancher
2.13.0 ≤
𝑥
< 2.13.6
CNA
suserancher
2.14.0 ≤
𝑥
< 2.14.2
CNA