Threat intelligence dashboard
CVE-2026-88804critical

Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.

Risk score

9.6

CVSS 3.1

Vendor
SUSE
Product
Rancher
CWE
CWE-79
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Rancher

SUSE

Version / rangeStatusType
2.15.0 to before 2.15.2affectedsemver
2.14.0 to before 2.14.6affectedsemver
2.13.0 to before 2.13.10affectedsemver
2.12.0 to before 2.12.14affectedsemver
2.11.0se to before 2.11.18affectedsemver

Technical metrics

9.6

CVSS 3.1

Severity
critical
Source
suse
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H