<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:05:04.347931+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-224903</id>
    <title>EUVD-2026-224903</title>
    <updated>2026-10-03T10:05:04.409106+00:00</updated>
    <content>EUVD-2026-224903</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-224903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-43759</id>
    <title>fkie_cve-2022-43759</title>
    <updated>2026-10-03T10:05:04.409142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-43759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7m72-mh5r-6j3r</id>
    <title>GHSA-7m72-mh5r-6j3r — Privilege escalation in project role template binding (PRTB) and -promoted roles</title>
    <updated>2026-10-03T10:05:04.409176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact</p>
<p>An issue was discovered in Rancher versions from 2.5.0 up to and including 2.5.16 and from 2.6.0 up to and including 2.6.9, where an authorization logic flaw allows privilege escalation via project role template binding (PRTB) and `-promoted` roles. This issue is not present in Rancher 2.7 releases.</p>
<p>Note: Consult Rancher [documentation](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/cluster-and-project-roles) for more information about cluster and project roles and [KB 000020097](https://www.suse.com/support/kb/doc/?id=000020097) for information about `-promoted` roles.</p>
<p>This privilege escalation is possible for users with access to the `escalate` verb on PRTBs (`projectroletemplatebindings.management.cattle.io`), including users with `*` verbs on PRTBs (see notes below for more information). These users can escalate permissions for any `-promoted` resource (see the table below for a full enumeration) in any cluster where they have a PRTB granting such permissions in at least one project in the cluster.</p>
<p>On a default Rancher setup, only the following roles have such permissions:</p>
<p>1. Project Owner
2. Manage Project Members</p>
<p>These roles have permissions to affect the following resources:</p>
<p>| Resource | API Group | Affected Rancher version |
| - | - | - |
| navlinks | ui.cattle.io | 2.6 |
| nodes | "" | 2.6 |
| persistentvolumes | "" | 2.5, 2.6 |
| persis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7m72-mh5r-6j3r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-43759</id>
    <title>gsd-2022-43759</title>
    <updated>2026-10-03T10:05:04.409251+00:00</updated>
    <content>gsd-2022-43759</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-43759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197</id>
    <title>WID-SEC-W-2023-0197 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:05:04.409265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, seine Rechte zu erweitern und Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197"/>
  </entry>
</feed>
