Rancher是Rancher组织开源的一个开源容器管理平台,专为在生产环境中部署容器的组织而构建。 Rancher 2.13.6版本之前的2.13.x版本和2.14.2版本之前的2.14.x版本存在授权问题漏洞,该漏洞源于Rancher Github身份验证提供程序的团队成员扩展中存在不正确的身份验证缓存,导致任何登录用户获得主体访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44947 | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher | |
| CVE-2026-44949 | Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace m | |
| CVE-2026-44948 | Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler | |
| CVE-2026-44946 | SAML Authentication Replay in Rancher |
No comments yet