Stored Cross-Site Scripting Vulnerability in SUSE Rancher UI
CVE-2026-88804

9.6CRITICAL

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-88804?

This vulnerability allows remote attackers to perform a stored cross-site scripting (XSS) attack by exploiting unauthenticated updates to public UI settings in the Rancher interface. It affects multiple versions of SUSE Rancher, enabling potential unauthorized access and manipulation of sensitive data by injecting malicious scripts that execute in users' browsers when they interact with the compromised UI.

Affected Version(s)

Rancher 2.15.0 < 2.15.2

Rancher 2.14.0 < 2.14.6

Rancher 2.13.0 < 2.13.10

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stopvvar@proton.me
.