CVE-2026-88804
EUVD-2026-8834028.09.2026, 16:17
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| suse | rancher | 2.15.0 ≤ 𝑥 < 2.15.2 | CNA |
| suse | rancher | 2.14.0 ≤ 𝑥 < 2.14.6 | CNA |
| suse | rancher | 2.13.0 ≤ 𝑥 < 2.13.10 | CNA |
| suse | rancher | 2.12.0 ≤ 𝑥 < 2.12.14 | CNA |
| suse | rancher | 𝑥 < 2.11.18 | CNA |