HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-41053Published Modified CNA suse

CVE-2026-41053: Over-inclusive team membership expansion in GitHub App authentication provider for Rancher

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
2.13.6
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

Fix available

2.13.62.14.2
Affected packages
  • SUSE / Rancher
    < 2.14.2 (from 2.14.0) · < 2.13.6 (from 2.13.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References