CVE-2026-55997
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rancher | rancher | 2.14.0 < 2.14.4 | affected |
| rancher | rancher | 2.13.0 < 2.13.8 | affected |
Weaknesses
- CWE-312: CWE-312 Cleartext storage of sensitive information
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55997
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.