<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T12:32:06.622582+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329725</id>
    <title>EUVD-2026-329725</title>
    <updated>2026-10-05T12:32:06.708429+00:00</updated>
    <content>EUVD-2026-329725</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44939</id>
    <title>fkie_cve-2026-44939</title>
    <updated>2026-10-05T12:32:06.708466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint  /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mhc6-2gfq-xx62</id>
    <title>GHSA-mhc6-2gfq-xx62 — Rancher vulnerable to command injection through unsanitized YAML parameter</title>
    <updated>2026-10-05T12:32:06.708519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact
A critical command injection vulnerability has been identified in the Rancher Manager cluster import endpoint  `/v3/import/{token}_{clusterId}.yaml` through unsanitized YAML parameters. This endpoint accepts an `authImage` query parameter that is rendered without sanitization into a generated Kubernetes manifest template. By including URL-encoded newlines in the parameter value, an attacker can break out of the `image:` field to inject arbitrary YAML keys and malicious configurations, such as commands to execute malicious containers.</p>
<p>Exploitation of this vulnerability requires the following conditions to be met:
- Attackers must obtain a valid cluster registration token (these tokens may be exposed, for example, through documentation, screenshots, or insecure communication channels).
- The victim’s cluster operator must execute `kubectl apply` against a maliciously crafted URL.</p>
<p>When a victim applies this compromised manifest using `kubectl apply`, a DaemonSet is deployed with the injected configuration. This DaemonSet:
- Runs on all control-plane nodes with `hostNetwork: true` enabled.
- Uses the `cattle` service account, which possesses `cluster-admin` privileges.
- Mounts `/etc/kubernetes` directly from the host.
- Executes attacker-controlled commands via the injected `command:` field.</p>
<p>An attacker who successfully exploits this vulnerability could:</p>
<p>- Achieve full control over downstream Kubernetes clusters.
- Execute arbitrary code on control-plane nodes w…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mhc6-2gfq-xx62"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716</id>
    <title>WID-SEC-W-2026-1716 — Rancher: Mehrere Schwachstellen</title>
    <updated>2026-10-05T12:32:06.708665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Befehle zu injizieren und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716"/>
  </entry>
</feed>
