<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:11:08.082792+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39967</id>
    <title>EUVD-2026-39967</title>
    <updated>2026-10-04T01:11:08.189080+00:00</updated>
    <content>EUVD-2026-39967</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10676</id>
    <title>fkie_cve-2020-10676</title>
    <updated>2026-10-04T01:11:08.189118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8vhc-hwhc-cpj4</id>
    <title>GHSA-8vhc-hwhc-cpj4 — Rancher users retain access after moving namespaces into projects they don't have access to</title>
    <updated>2026-10-04T01:11:08.189151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact
A vulnerability was identified in which users with update privileges on a namespace, can move that namespace into a project they don't have access to. After the namespace transfer is completed, their previous permissions are still preserved, which enables them to gain access to project-specific resources (such as [project secrets](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/kubernetes-resources-setup/secrets#creating-secrets-in-projects)). In addition, resources in the namespace will now count toward the [quota limit](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/manage-projects/manage-project-resource-quotas/about-project-resource-quotas) of the new project, potentially causing availability issues.</p>
<p>User with roles `Project Owner` and `Project Member` on the source project can exploit this vulnerability; however, this would also apply to custom roles with similar privileges.</p>
<p>The patched version include an improved RBAC mechanism, which checks if the user has the correct permissions before the namespace move takes place.</p>
<p>### Patches
Patched versions include releases `2.6.13`, `2.7.4` and later versions.</p>
<p>### Workarounds
There is no direct mitigation besides updating Rancher to a patched version.</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquirie…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8vhc-hwhc-cpj4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10676</id>
    <title>gsd-2020-10676</title>
    <updated>2026-10-04T01:11:08.189200+00:00</updated>
    <content>gsd-2020-10676</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1340</id>
    <title>WID-SEC-W-2023-1340 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:11:08.189214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsvorkehrungen zu umgehen oder einen Cross Site Scripting angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1340"/>
  </entry>
</feed>
