CVE-2026-41053 Details
Description
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
A vulnerability exists in Rancher versions 2.13 prior to 2.13.6 and 2.14 prior to 2.14.2, within the GitHub App authentication provider. The issue arises from incorrect caching of authentication data, which allows any logged-in user to gain principal access to all teams within a GitHub organization, rather than just the teams they belong to. This over-expansion of team memberships can lead to unauthorized access to resources and permissions, especially if the teams are linked to Rancher login allowlists or RBAC roles.
Users can upgrade to Rancher versions 2.14.2 or 2.13.6. If an immediate upgrade is not possible, consider disabling the GitHub App authentication provider, removing or restricting team-based group principals from allowed principalIds, auditing and temporarily removing RBAC bindings that reference GitHub App team principals, or disabling provider refresh to clean up inflated group membership.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh | [email protected] | PatchVendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-303 | Incorrect Implementation of Authentication Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| suse rancher | >= 2.13.0, < 2.13.6 >= 2.14.0, < 2.14.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |