<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:10:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-224903</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-224903</link>
      <description>EUVD-2026-224903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-224903</guid>
    </item>
    <item>
      <title>fkie_cve-2022-43759</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-43759</link>
      <description>&lt;p&gt;A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-43759</guid>
    </item>
    <item>
      <title>GHSA-7m72-mh5r-6j3r — Privilege escalation in project role template binding (PRTB) and -promoted roles</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7m72-mh5r-6j3r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An issue was discovered in Rancher versions from 2.5.0 up to and including 2.5.16 and from 2.6.0 up to and including 2.6.9, where an authorization logic flaw allows privilege escalation via project role template binding (PRTB) and `-promoted` roles. This issue is not present in Rancher 2.7 releases.&lt;/p&gt;
&lt;p&gt;Note: Consult Rancher [documentation](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/cluster-and-project-roles) for more information about cluster and project roles and [KB 000020097](https://www.suse.com/support/kb/doc/?id=000020097) for information about `-promoted` roles.&lt;/p&gt;
&lt;p&gt;This privilege escalation is possible for users with access to the `escalate` verb on PRTBs (`projectroletemplatebindings.management.cattle.io`), including users with `*` verbs on PRTBs (see notes below for more information). These users can escalate permissions for any `-promoted` resource (see the table below for a full enumeration) in any cluster where they have a PRTB granting such permissions in at least one project in the cluster.&lt;/p&gt;
&lt;p&gt;On a default Rancher setup, only the following roles have such permissions:&lt;/p&gt;
&lt;p&gt;1. Project Owner
2. Manage Project Members&lt;/p&gt;
&lt;p&gt;These roles have permissions to affect the following resources:&lt;/p&gt;
&lt;p&gt;| Resource | API Group | Affected Rancher version |
| - | - | - |
| navlinks | ui.cattle.io | 2.6 |
| nodes | &amp;#34;&amp;#34; | 2.6 |
| persistentvolumes | &amp;#34;&amp;#34; | 2.5, 2.6 |
| persis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An issue was discovered in Rancher versions from 2.5.0 up to and including 2.5.16 and from 2.6.0 up to and including 2.6.9, where an authorization logic flaw allows privilege escalation via project role template binding (PRTB) and `-promoted` roles. This issue is not present in Rancher 2.7 releases.&lt;/p&gt;
&lt;p&gt;Note: Consult Rancher [documentation](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/cluster-and-project-roles) for more information about cluster and project roles and [KB 000020097](https://www.suse.com/support/kb/doc/?id=000020097) for information about `-promoted` roles.&lt;/p&gt;
&lt;p&gt;This privilege escalation is possible for users with access to the `escalate` verb on PRTBs (`projectroletemplatebindings.management.cattle.io`), including users with `*` verbs on PRTBs (see notes below for more information). These users can escalate permissions for any `-promoted` resource (see the table below for a full enumeration) in any cluster where they have a PRTB granting such permissions in at least one project in the cluster.&lt;/p&gt;
&lt;p&gt;On a default Rancher setup, only the following roles have such permissions:&lt;/p&gt;
&lt;p&gt;1. Project Owner
2. Manage Project Members&lt;/p&gt;
&lt;p&gt;These roles have permissions to affect the following resources:&lt;/p&gt;
&lt;p&gt;| Resource | API Group | Affected Rancher version |
| - | - | - |
| navlinks | ui.cattle.io | 2.6 |
| nodes | &amp;#34;&amp;#34; | 2.6 |
| persistentvolumes | &amp;#34;&amp;#34; | 2.5, 2.6 |
| persis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7m72-mh5r-6j3r</guid>
    </item>
    <item>
      <title>gsd-2022-43759</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-43759</link>
      <description>gsd-2022-43759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-43759</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0197 — Rancher: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, seine Rechte zu erweitern und Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, seine Rechte zu erweitern und Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0197</guid>
    </item>
  </channel>
</rss>
