VYPR
Critical severity9.6NVD Advisory· Published Sep 28, 2026

CVE-2026-88804

CVE-2026-88804

Description

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Rancher/Rancherllm-fuzzy
    Range: <2.15.2, <2.14.6, <2.13.10, <2.12.14, <2.11.18
  • Range: <2.15.2, <2.14.6, <2.13.10, <2.12.14, <2.11.18

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.