Stored Cross-Site Scripting Vulnerability in SUSE Rancher UI
CVE-2026-88804
9.6CRITICAL
What is CVE-2026-88804?
This vulnerability allows remote attackers to perform a stored cross-site scripting (XSS) attack by exploiting unauthenticated updates to public UI settings in the Rancher interface. It affects multiple versions of SUSE Rancher, enabling potential unauthorized access and manipulation of sensitive data by injecting malicious scripts that execute in users' browsers when they interact with the compromised UI.
Affected Version(s)
Rancher 2.15.0 < 2.15.2
Rancher 2.14.0 < 2.14.6
Rancher 2.13.0 < 2.13.10