CVE-2026-41053 PUBLISHED

Over-inclusive team membership expansion in GitHub App authentication provider for Rancher

Assigner: suse
Reserved: 16.04.2026 Published: 30.06.2026 Updated: 30.06.2026

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor SUSE
Product Rancher
Versions Default: unaffected
  • affected from 2.14.0 to 2.14.2 (excl.)
  • affected from 2.13.0 to 2.13.6 (excl.)

References

Problem Types

  • CWE-303 Incorrect implementation of authentication algorithm CWE

Impacts

  • CAPEC-233 Privilege Escalation