Long-lived Registration Token Vulnerability in Rancher
CVE-2026-55997

8.8HIGH

Key Information:

Vendor

Rancher

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-55997?

Rancher has a security vulnerability where long-lived registration tokens are issued for authenticating nodes. These tokens, stored in plaintext without any expiration, can be directly accessed through the Rancher API, etcd, or via automated scripts. This exposure allows malicious actors to potentially capture these tokens and use them to register unauthorized nodes into the cluster at any time, posing a significant security risk.

Affected Version(s)

rancher 2.14.0 < 2.14.4

rancher 2.13.0 < 2.13.8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.