---
cve: "CVE-2026-41053"
severity: "HIGH"
cvss: 8.8
epss: "45%"
vendor: "SUSE"
kev: false
exploited: false
published: "2026-06-30 12:16:23"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-04T07:43:04+02:00"
---

# CVE-2026-41053

> 8.8 HIGH · 🧪 PoC

## Beschreibung

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 93a5abcbed0d07643e1cb9d2f642eeac65a14377 (Commit)
- 1bb24fe965ab9a801cd28447cc97df28db58cbd9 (Commit)

## Referenzen

- <https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-41053) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
