登出时凭据清理不当,可能导致远程攻击者在账户注销后仍保留访问凭据。受影响的版本为 SUSE Rancher 2.15 至 2.15.2 之前的所有版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88804 | 9.6 CRITICAL | Unauthenticated update of public UI settings leading to stored cross-site scripting in Ran |
| CVE-2026-88808 | 8.8 HIGH | Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-name |
| CVE-2026-78424 | 8.8 HIGH | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution o |
| CVE-2026-93538 | 7.1 HIGH | Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agen |
| CVE-2026-93540 | 6.5 MEDIUM | Fleet applies namespace labels and annotations without the bundle's service account privil |
| CVE-2026-93537 | 6.5 MEDIUM | Path traversal in Fleet Helm valuesFiles allows disclosure of files outside the bundle dir |
| CVE-2026-93539 | 5.4 MEDIUM | Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver |
No comments yet