<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:43:48.643604+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272999</id>
    <title>EUVD-2026-272999</title>
    <updated>2026-10-03T12:43:48.712024+00:00</updated>
    <content>EUVD-2026-272999</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22036</id>
    <title>fkie_cve-2024-22036</title>
    <updated>2026-10-03T12:43:48.712062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot
 jail and gain root access to the Rancher container itself. In 
production environments, further privilege escalation is possible based 
on living off the land within the Rancher container itself. For the test
 and development environments, based on a –privileged Docker container, 
it is possible to escape the Docker container and gain execution access 
on the host system.</p>
<p>This issue affects rancher: from 2.7.0 before 2.7.16, from 2.8.0 before 2.8.9, from 2.9.0 before 2.9.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-22036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h99m-6755-rgwc</id>
    <title>GHSA-h99m-6755-rgwc — Rancher Remote Code Execution via Cluster/Node Drivers</title>
    <updated>2026-10-03T12:43:48.712102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact
A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the `chroot` jail and gain root access to the Rancher container itself. In production environments, further privilege escalation is possible based on living off the land within the Rancher container itself. For the test and development environments, based on a –privileged Docker container, it is possible to escape the Docker container and gain execution access on the host system.</p>
<p>This happens because:
- During startup, Rancher appends the `/opt/drivers/management-state/bin` directory to the `PATH` environment variable.
- In Rancher, the binaries `/usr/bin/rancher-machine`, `/usr/bin/helm_v3`, and `/usr/bin/kustomize` are assigned a UID of 1001 and a GID of 127 instead of being owned by the root user.
- Rancher employs a jail mechanism to isolate the execution of node drivers from the main process. However, the drivers are executed with excessive permissions.
- During the registration of new node drivers, its binary is executed with the same user as the parent process, which could enable an attacker to gain elevated privileges by registering a malicious driver.
- Lack of validation on the driver file type, which allows symbolic links to be used.</p>
<p>Please consult the associated  [MITRE ATT&amp;CK - Technique - Privilege Escalation](https://attack.mitre.org/tactics/TA0004/) and [MITRE ATT&amp;CK - Technique - Execution](https://attack.mitre.org/tactics/TA0002/) for furth…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h99m-6755-rgwc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-22036</id>
    <title>gsd-2024-22036</title>
    <updated>2026-10-03T12:43:48.712160+00:00</updated>
    <content>gsd-2024-22036</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-22036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</id>
    <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-03T12:43:48.712174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</id>
    <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-03T12:43:48.712208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3273</id>
    <title>WID-SEC-W-2024-3273 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:43:48.712236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um Informationen offenzulegen, erhöhte Rechte zu erlangen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3273"/>
  </entry>
</feed>
