Privilege Escalation Vulnerability in Rancher by Rancher Labs
CVE-2026-41052

9.4CRITICAL

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
29 June 2026

What is CVE-2026-41052?

A vulnerability has been identified in Rancher that allows users with the Project Owner role to escalate their privileges due to improper privilege handling. This affects Rancher versions 2.14 prior to 2.14.2, 2.13 prior to 2.13.6, and 2.12 prior to 2.12.10, potentially allowing for unauthorized access or control over project resources.

Affected Version(s)

Rancher 2.12.0 < 2.12.10

Rancher 2.13.0 < 2.13.6

Rancher 2.14.0 < 2.14.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Radtke Benedikt <Radtke@iabg.de> - github.com/Trolldemorted and Munier Marc <Munier@iabg.de> - github.com/mmunier
.