TGViewer
Netlas.io Netlas.io @netlas · 2.32K subscribers
Post #639 180
CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating 🔥

An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.

Search at Netlas.io:
👉 Link: https://nt.ls/dtxM5
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"

Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
  • ❤ 1
  • 🔥 1
More from @netlas
  1. Sep 25, 2026CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating 🔥 Rec…
  2. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
  3. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  4. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  5. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  6. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →