CVE-2026-88804 PUBLISHED

Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher

Assigner: suse
Reserved: 10.09.2026 Published: 28.09.2026 Updated: 28.09.2026

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor SUSE
Product Rancher
Versions Default: unaffected
  • affected from 2.15.0 to 2.15.2 (excl.)
  • affected from 2.14.0 to 2.14.6 (excl.)
  • affected from 2.13.0 to 2.13.10 (excl.)
  • affected from 2.12.0 to 2.12.14 (excl.)
  • affected from 2.11.0se to 2.11.18 (excl.)

Credits

  • stopvvar@proton.me finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-104 Cross Zone Scripting