Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
References
| Link | Resource |
|---|---|
| https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh | Patch Vendor Advisory Mitigation |
Configurations
Configuration 1 (hide)
|
History
02 Jul 2026, 19:57
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Suse
Suse rancher |
|
| References | () https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh - Patch, Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:* |
30 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 12:16
Updated : 2026-07-02 19:57
NVD link : CVE-2026-41053
Mitre link : CVE-2026-41053
CVE.ORG link : CVE-2026-41053
JSON object : View
Products Affected
suse
- rancher
CWE
CWE-303
Incorrect Implementation of Authentication Algorithm
