CRITICAL🇵🇱 Wersja polska

CVE-2026-41052

CVSS 9.4v4.0pub. 2026-06-29upd. 2026-07-02

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

🤖 AI Analysis
How it works

The error results from improper permission handling (CWE-305 — Authentication Bypass by Primary Weakness), which does not properly verify the boundaries of the Project Owner role. A user with this role can exploit the vulnerability to gain permissions that exceed their assigned scope. The attack is possible remotely, without user interaction, however it requires possessing an account with the Project Owner role.

Impact

An attacker can obtain unauthorized access to resources and operations reserved for higher-level roles, which may lead to complete takeover of control over the Rancher environment, including managed Kubernetes clusters.

Mitigation & patch

Rancher should be updated to version 2.12.10, 2.13.6, or 2.14.2 (depending on the branch in use). Details are available in the official security advisory from the vendor: https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744

Who is affected

Rancher in versions 2.12 before 2.12.10, 2.13 before 2.13.6, and 2.14 before 2.14.2.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • SUSE Rancher

    APP
    Suse
    2.12.0 – 2.12.10 (excl.)2.13.0 – 2.13.6 (excl.)2.14.0 – 2.14.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-44946CRITICAL9.5PL ✓same product

SAML authentication replay w Rancher — brak wymuszenia jednorazowego użycia asercji

CVE-2023-22647CRITICAL9.9PL ✓same product

SUSE Rancher: eskalacja uprawnień przez manipulację Kubernetes secrets

CVE-2023-22651CRITICAL9.9PL ✓same product

SUSE Rancher – privilege escalation przez błędną konfigurację admission Webhook

CVE-2022-43757CRITICAL9.9PL ✓same product

SUSE Rancher: przechowywanie poświadczeń w postaci jawnego tekstu

CVE-2021-36782CRITICAL9.9PL ✓same product

SUSE Rancher: przechowywanie wrażliwych danych w postaci jawnej