CVE-2026-71404

🟡 Monitoruj

Błąd w Rancher Manager pozwala na eskalację uprawnień przez modyfikację ról.

CVSS
8.7
EPSS
0.3%
Exploit
none
Vendor
suse
Opis źródłowy (NVD)

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-03 15:17:32 UTC
Ostatnia modyfikacja (NVD)2026-09-18 14:58:34 UTC
Referencje