Ghostwire

CVE-2026-41053: Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused...

HIGH CVSS 8.8 Exploit Available

Published: June 30, 2026 | Last Modified: June 30, 2026

Description

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References