Critical XSS Vulnerability in SUSE Rancher Exposes Admin Sessions
Article Content
- •CVE-2026-88804 allows unauthenticated XSS attacks in SUSE Rancher.
- •Affected versions include Rancher 2.15, 2.14, 2.13, 2.12, and 2.11.
- •Patch available; immediate upgrade is recommended to mitigate risks.
A critical vulnerability (CVE-2026-88804) in SUSE Rancher allows unauthenticated remote attackers to execute stored cross-site scripting (XSS) attacks via public UI settings. This affects Rancher versions 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14, and 2.11 before 2.11.18. Attackers can modify settings that render raw HTML on the login page, potentially leading to session hijacking or unauthorized access. The vulnerability has a CVSS score of 9.6, indicating a critical impact on confidentiality, integrity, and availability. A patch has been released, and administrators are urged to upgrade to the fixed versions immediately. Organizations should also monitor public UI settings for unexpected changes and restrict network access to the Rancher server. The vulnerability was disclosed on September 28, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-88804 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…