CVE-2026-41053

EUVD-2026-40297
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.51%
Affected Products (NVD)
VendorProductVersion
suserancher
2.13.0 ≤
𝑥
< 2.13.6
suserancher
2.14.0 ≤
𝑥
< 2.14.2
𝑥
= Vulnerable software versions