User Resource Immutability Flaw in Rancher Manager by Rancher
CVE-2026-71403

6.1MEDIUM

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-71403?

A vulnerability in Rancher Manager allows an authenticated user with update privileges on users management to bypass resource immutability constraints for username and principalIds. This enables the malicious user to inject a foreign identity provider principal into any user account. Consequently, if the legitimate user later logs in, their account gets associated with the attacker's role bindings, leading to unauthorized access and potential takeover of their account.

Affected Version(s)

Rancher 0 < 2.15.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrej TomÄŤi
.