CVE-2026-88804

EUVD-2026-88340
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
suseCNA
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
suserancher
2.15.0 ≤
𝑥
< 2.15.2
CNA
suserancher
2.14.0 ≤
𝑥
< 2.14.6
CNA
suserancher
2.13.0 ≤
𝑥
< 2.13.10
CNA
suserancher
2.12.0 ≤
𝑥
< 2.12.14
CNA
suserancher
𝑥
< 2.11.18
CNA