CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating 🔥
An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.
Search at Netlas.io:
👉 Link: https://nt.ls/dtxM5
👉 Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
Post #639
180

- ❤ 1
- 🔥 1