CVE-2026-41053
published 2026-06-30CVE-2026-41053: Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any…
PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.37%
29.1th percentile
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | rancher_rancher | >= 0 < 0.0.0-20260519172014-d0c047bbc6d2 | 0.0.0-20260519172014-d0c047bbc6d2 |
| github.com | rancher_rancher | >= 2.13.0 < 2.13.6 | 2.13.6 |
| github.com | rancher_rancher | >= 2.14.0 < 2.14.2 | 2.14.2 |
| suse | rancher | >= 2.13.0 < 2.13.6 | 2.13.6 |
| suse | rancher | >= 2.14.0 < 2.14.2 | 2.14.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
ghsa·2026-07-01
CVE-2026-41053 [HIGH] CWE-303 Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
### Impact
A vulnerability has been identified within Rancher Manager in the GitHub App authentication provider. When evaluating permissions, the provider incorrectly expands user team memberships to include all teams within the associated GitHub organization, rather than restricting access to the specific teams to which the user actually belongs.
Specifically, when a user authenticates via the GitHub App provider, Rancher's team membership evaluation logic incorrectly handles cached data. Instead of checking the user-specific list, the evaluation logic iterates over all teams defined within the entire GitHub organization. The authentication provider should consult the correctly cached, per-user me
VulDB
SUSE Rancher up to 2.13.5/2.14.1 incorrect implementation of authentication algorithm (GHSA-4j6x-2764-m8gh)
vuldb·2026-06-30·CVSS 8.8
CVE-2026-41053 [HIGH] SUSE Rancher up to 2.13.5/2.14.1 incorrect implementation of authentication algorithm (GHSA-4j6x-2764-m8gh)
A vulnerability classified as very critical has been found in SUSE Rancher up to 2.13.5/2.14.1. This issue affects some unknown processing. The manipulation leads to incorrect implementation of authentication algorithm.
This vulnerability is uniquely identified as CVE-2026-41053. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published