Vulnerability intelligence
CVE-2026-41053
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.5%
Riskier than 43% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026
Coverage timeline
-
Rancher CVE-2026-44939 lets attackers hijack Kubernetes clusterssecurityonline.info · Jun 2, 2026