CVE-2026-71403 - CERT CVE
ID CVE-2026-71403
Sažetak A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings. This issue affects Rancher: before 2.15.1.
Reference
CVSS
Base: 6.1
Impact: 5.2
Exploitability:0.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Zadnje važnije ažuriranje 03-09-2026 - 15:17
Objavljeno 03-09-2026 - 15:17