Long-lived Registration Token Vulnerability in Rancher
CVE-2026-55997
8.8HIGH
What is CVE-2026-55997?
Rancher has a security vulnerability where long-lived registration tokens are issued for authenticating nodes. These tokens, stored in plaintext without any expiration, can be directly accessed through the Rancher API, etcd, or via automated scripts. This exposure allows malicious actors to potentially capture these tokens and use them to register unauthorized nodes into the cluster at any time, posing a significant security risk.
Affected Version(s)
rancher 2.14.0 < 2.14.4
rancher 2.13.0 < 2.13.8
