CVE-2026-88805: fallo de gravedad alta en SUSE Rancher
Session Not Revoked Server-Side on Logout in Rancher
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.1epss 0.3%
probabilidad de explotación
0.3%top 85% de las CVE
explotación observada
noninguna fuente lo reporta
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Productos afectados
SUSE · RancherCVEs relacionadas — SUSE Rancher
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-36782CRITICALRancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectEPSS 4.2%CVE-2022-31249HIGH[RANCHER] OS command injection in Rancher and FleetEPSS 3.8%CVE-2022-43755HIGHRancher: Non-random authentication tokenEPSS 1.7%CVE-2021-25313HIGHRancher: XSS on /v3/cluster/EPSS 1.5%CVE-2026-44939CRITICALCommand injection through unsanitized YAML parameter in RancherEPSS 1.3%CVE-2021-36776HIGHSteve API proxy impersonationEPSS 1.1%