CVE-2026-88804Critical· 9.6▾ MidnightAn unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88805High· 8.1Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out
CVE-2026-75034High· 7.4A flaw was found in Rancher Manager
CVE-2026-71403Medium· 6.1A flaw was found in Rancher Manager
CVE-2026-71404High· 8.7A flaw was found in Rancher Manager
CVE-2026-75033High· 7.7A flaw was found in Rancher Manager
CVE-2026-75035High· 7.7A flaw was found in Rancher Manager