CVE-2026-88805: falha de alta gravidade em SUSE Rancher
Session Not Revoked Server-Side on Logout in Rancher
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.1epss 0.3%
probabilidade de exploração
0.3%top 85% das CVEs
exploração observada
nãonenhuma fonte reporta
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Produtos afetados
SUSE · RancherCVEs relacionadas — SUSE Rancher
No mesmo produto, das mais perigosas para as menos.
CVE-2021-36782CRITICALRancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectEPSS 4.2%CVE-2022-31249HIGH[RANCHER] OS command injection in Rancher and FleetEPSS 3.8%CVE-2022-43755HIGHRancher: Non-random authentication tokenEPSS 1.7%CVE-2021-25313HIGHRancher: XSS on /v3/cluster/EPSS 1.5%CVE-2026-44939CRITICALCommand injection through unsanitized YAML parameter in RancherEPSS 1.3%CVE-2021-36776HIGHSteve API proxy impersonationEPSS 1.1%