CVE Vulnerabilities

CVE-2026-41053

Incorrect Implementation of Authentication Algorithm

Published: Jun 30, 2026 | Modified: Jul 02, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

NameVendorStart VersionEnd Version
RancherSuse2.13.0 (including)2.13.6 (excluding)
RancherSuse2.14.0 (including)2.14.2 (excluding)

References