Rancher是Rancher组织开源的一个开源容器管理平台,专为在生产环境中部署容器的组织而构建。 Rancher 2.13.7及之前的2.13.x版本和2.14.3及之前的2.14.x版本存在权限许可和访问控制问题漏洞,该漏洞源于遗留项目角色模板绑定(PRTB)协调器缺乏清理机制,可能导致用户在管理员从RoleTemplate删除权限后保留未经授权的Pod Security Admission(PSA)权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41053 | 8.8 HIGH | Over-inclusive team membership expansion in GitHub App authentication provider for Rancher |
| CVE-2026-44949 | Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace m | |
| CVE-2026-44948 | Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler | |
| CVE-2026-44946 | SAML Authentication Replay in Rancher |
No comments yet