🔐 CVE Alert

CVE-2026-41052

UNKNOWN 0.0

Rancher Privilege Escalation from Project Owner to Host

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

CWE CWE-305
Vendor suse
Product rancher
Published Jun 29, 2026
Last Updated Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for suse rancher

Be the first to know when new unknown vulnerabilities affecting suse rancher are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

SUSE / Rancher
2.12.0 < 2.12.10 2.13.0 < 2.13.6 2.14.0 < 2.14.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744

Credits

Radtke Benedikt <[email protected]> - github.com/Trolldemorted and Munier Marc <[email protected]> - github.com/mmunier