CVE-2026-88804

Summary

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.

Affected Software

VendorProductVersion RangeStatus
SUSERancher2.15.0 < 2.15.2affected
SUSERancher2.14.0 < 2.14.6affected
SUSERancher2.13.0 < 2.13.10affected
SUSERancher2.12.0 < 2.12.14affected
SUSERancher2.11.0se < 2.11.18affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References