Rancher Webhook是Rancher公司的一款消息队列组件。 Rancher Webhook 0.7.0至0.7.10之前版本、0.8.0至0.8.7之前版本、0.9.0至0.9.6之前版本以及0.10.0至0.10.7之前版本存在授权问题漏洞,该漏洞源于FleetWorkspace准入路径允许在Rancher webhook处理器中产生副作用,可能导致未经身份验证的攻击者通过网络访问集群内rancher-webhook服务,提交特制的准入有效载荷,从而创建具有攻击者选择的身份数据的工作区相关K
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41053 | 8.8 HIGH | Over-inclusive team membership expansion in GitHub App authentication provider for Rancher |
| CVE-2026-44947 | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher | |
| CVE-2026-44948 | Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler | |
| CVE-2026-44946 | SAML Authentication Replay in Rancher |
No comments yet