Privilege Escalation Vulnerability in Rancher by Rancher Labs
CVE-2026-41052
9.4CRITICAL
What is CVE-2026-41052?
A vulnerability has been identified in Rancher that allows users with the Project Owner role to escalate their privileges due to improper privilege handling. This affects Rancher versions 2.14 prior to 2.14.2, 2.13 prior to 2.13.6, and 2.12 prior to 2.12.10, potentially allowing for unauthorized access or control over project resources.
Affected Version(s)
Rancher 2.12.0 < 2.12.10
Rancher 2.13.0 < 2.13.6
Rancher 2.14.0 < 2.14.2
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Radtke Benedikt <Radtke@iabg.de> - github.com/Trolldemorted and Munier Marc <Munier@iabg.de> - github.com/mmunier