Skip to content

Warning: Critical Cross-site Scripting (XSS) in Rancher - Kubernetes management platform, Patch I...

Ccb.Belgium.Be • September 30, 2026

SUSE Rancher versions: 2.14.0 before 2.14.6, 2.15.0 before 2.15.2, 2.13.0 before 2.13.10, 2.12.0 before 2.12.14, 2.11.0se before 2.11.1

Type: CWE-79: Improper neutralisation of input during web page generation (cross-site scripting)

CVE/CVSS: CVE-2026-88804: 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)

SUSE Rancher is an enterprise-grade, open-source Kubernetes management platform. On Tuesday 28 September 2026, they disclosed the critical vulnerability CVE-2026-88804.

If a remote attacker, who injects a malicious script (cross-site scripting), succeeds in making users interact with them, that can allow them to exploit this vulnerability to steal admin sessions. Exploiting this vulnerability can have a high impact on all three aspects of the CIA triad (Confidentiality, Integrity, Availability).

As of the time of writing this advisory (2026-09-29) there is no publicly available proof-of-concept, nor is there any no proof-of-exploitation available online.

CVE-2026-88804 allows unauthenticated, network-based attackers to update public UI settings with the purpose of executing a stored cross-site scripting attack. They use those scripts to steal or compromise administrative session tokens and credentials to gain unauthorised (admin) access to Rancher.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case of an intrusion, you can report an incident via . While patching appliances or software to the newest version may protect against future exploitation, it does not remediate historic compromise.

Extracted Entities

Attack Types (1)

Platforms (1)