Critical severityNVD Advisory· Published Jun 29, 2026· Updated Jun 30, 2026
Rancher Privilege Escalation from Project Owner to Host
CVE-2026-41052
Description
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.14.0, < 2.14.2 | 2.14.2 |
github.com/rancher/rancherGo | >= 2.13.0, < 2.13.6 | 2.13.6 |
github.com/rancher/rancherGo | >= 2.12.0, < 2.12.10 | 2.12.10 |
github.com/rancher/rancherGo | < 0.0.0-20260513182521-2800aaac25b5 | 0.0.0-20260513182521-2800aaac25b5 |
Affected products
3- osv-coords2 versions
< 1.8.1-r32+ 1 more
- (no CPE)range: < 1.8.1-r32
- (no CPE)range: < 1.8.1-r28
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-vx8h-4prv-g744ghsaADVISORY
- github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-41052ghsaADVISORY
- github.com/rancher/rancher/commit/2800aaac25b5a2c448f800e1f46dghsaWEB
- github.com/rancher/rancher/pull/55061ghsaWEB
News mentions
0No linked articles in our index yet.