CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:57

Type Values Removed Values Added
First Time Suse
Suse rancher
References () https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh - () https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh - Patch, Vendor Advisory, Mitigation
CPE cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*

30 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 12:16

Updated : 2026-07-02 19:57


NVD link : CVE-2026-41053

Mitre link : CVE-2026-41053

CVE.ORG link : CVE-2026-41053


JSON object : View

Products Affected

suse

  • rancher
CWE
CWE-303

Incorrect Implementation of Authentication Algorithm