High severity8.8NVD Advisory· Published Jun 29, 2026· Updated Jul 2, 2026
CVE-2026-41052
CVE-2026-41052
Description
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.14.0, < 2.14.2 | 2.14.2 |
github.com/rancher/rancherGo | >= 2.13.0, < 2.13.6 | 2.13.6 |
github.com/rancher/rancherGo | >= 2.12.0, < 2.12.10 | 2.12.10 |
github.com/rancher/rancherGo | < 0.0.0-20260513182521-2800aaac25b5 | 0.0.0-20260513182521-2800aaac25b5 |
Affected products
5- osv-coords3 versionspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester
< 0.0.20260723T184607-160000.1.1+ 2 more
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 1.8.1-r28
- (no CPE)range: < 1.8.1-r32
Patches
Vulnerability mechanics
References
5- github.com/rancher/rancher/security/advisories/GHSA-vx8h-4prv-g744nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-vx8h-4prv-g744ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41052ghsaADVISORY
- github.com/rancher/rancher/commit/2800aaac25b5a2c448f800e1f46dghsaWEB
- github.com/rancher/rancher/pull/55061ghsaWEB
News mentions
0No linked articles in our index yet.