← Back to CVE search

CVE-2026-41053

Rancher Github

Description

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

CVSS 8.8EPSS 0.45399999999999996%Risk 0.92
View source
Published
2026-06-30 12:16:23
Affected versions
<2.13.6, >=2.14,<2.14.2
Type
Critical software
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H