<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T23:47:03.394751+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09231</id>
    <title>bdu:2026-09231</title>
    <updated>2026-10-04T23:47:03.397957+00:00</updated>
    <content>bdu:2026-09231</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09231"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331528</id>
    <title>EUVD-2026-331528</title>
    <updated>2026-10-04T23:47:03.397992+00:00</updated>
    <content>EUVD-2026-331528</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331528"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41053</id>
    <title>fkie_cve-2026-41053</title>
    <updated>2026-10-04T23:47:03.398006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4j6x-2764-m8gh</id>
    <title>GHSA-4j6x-2764-m8gh — Rancher has over-inclusive team membership expansion in GitHub App authentication provider</title>
    <updated>2026-10-04T23:47:03.398034+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact
A vulnerability has been identified within Rancher Manager in the GitHub App authentication provider. When evaluating permissions, the provider incorrectly expands user team memberships to include all teams within the associated GitHub organization, rather than restricting access to the specific teams to which the user actually belongs.</p>
<p>Specifically, when a user authenticates via the GitHub App provider, Rancher's team membership evaluation logic incorrectly handles cached data. Instead of checking the user-specific list, the evaluation logic iterates over all teams defined within the entire GitHub organization. The authentication provider should consult the correctly cached, per-user membership list to assign the user's specific group permissions. Consequently, any authenticated user who belongs to at least one team in a GitHub organization is mistakenly granted `group principals` for every team within that entire organization during authentication and authorization checks.</p>
<p>This issue allows a malicious user who is a member of a low-privilege team within a GitHub organization to gain unauthorized access to or permissions for any other team in that organization. If those other teams are bound to Rancher login allowlists or RBAC roles (cluster-level, project-level, or global), the attacker can pass access checks that should otherwise fail, inheriting permissions they were never granted.</p>
<p>**Exploitation of this vulnerability requires the following conditions to b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4j6x-2764-m8gh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716</id>
    <title>WID-SEC-W-2026-1716 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-04T23:47:03.398082+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Befehle zu injizieren und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716"/>
  </entry>
</feed>
