<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:49:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-194160</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-194160</link>
      <description>EUVD-2026-194160</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-194160</guid>
    </item>
    <item>
      <title>fkie_cve-2023-22648</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22648</link>
      <description>&lt;p&gt;A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users 
while they are logged in the Rancher UI. This would cause the users to 
retain their previous permissions in Rancher, even if they change groups
 on Azure AD, for example, to a lower privileged group, or are removed 
from a group, thus retaining their access to Rancher instead of losing 
it.
This issue affects Rancher: from &amp;gt;= 2.6.7 before &amp;lt; 2.6.13, from &amp;gt;= 2.7.0 before &amp;lt; 2.7.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users 
while they are logged in the Rancher UI. This would cause the users to 
retain their previous permissions in Rancher, even if they change groups
 on Azure AD, for example, to a lower privileged group, or are removed 
from a group, thus retaining their access to Rancher instead of losing 
it.
This issue affects Rancher: from &amp;gt;= 2.6.7 before &amp;lt; 2.6.13, from &amp;gt;= 2.7.0 before &amp;lt; 2.7.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-22648</guid>
    </item>
    <item>
      <title>GHSA-vf6j-6739-78m8 — Rancher's Azure AD permission changes are not reflected on active sessions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vf6j-6739-78m8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;A bug has been identified in which permission changes in Azure AD are not reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it.&lt;/p&gt;
&lt;p&gt;### Impact
This issue only affects Rancher instances with Azure AD integration enabled, regardless of the [automatically refreshing settings](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/manage-users-and-groups#automatically-refreshing-user-information) which are enabled by default. The users that obtained a token (or kubeconfig) to access Rancher through the following sessions are affected by this issue:
1) Users using the Rancher UI.
2) Users using `kubectl` based on a `kubeconfig` downloaded through the Rancher UI.
3) Tokens created via the Rancher UI Create API Key feature.&lt;/p&gt;
&lt;p&gt;Note that the permission caching is persisted even when the Rancher Manager pod is restarted. The only way for a user to get the new permissions is to logout and login again.&lt;/p&gt;
&lt;p&gt;### Patches
Patched versions include releases `2.6.13`, `2.7.4` and later versions.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;A bug has been identified in which permission changes in Azure AD are not reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it.&lt;/p&gt;
&lt;p&gt;### Impact
This issue only affects Rancher instances with Azure AD integration enabled, regardless of the [automatically refreshing settings](https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/authentication-config/manage-users-and-groups#automatically-refreshing-user-information) which are enabled by default. The users that obtained a token (or kubeconfig) to access Rancher through the following sessions are affected by this issue:
1) Users using the Rancher UI.
2) Users using `kubectl` based on a `kubeconfig` downloaded through the Rancher UI.
3) Tokens created via the Rancher UI Create API Key feature.&lt;/p&gt;
&lt;p&gt;Note that the permission caching is persisted even when the Rancher Manager pod is restarted. The only way for a user to get the new permissions is to logout and login again.&lt;/p&gt;
&lt;p&gt;### Patches
Patched versions include releases `2.6.13`, `2.7.4` and later versions.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vf6j-6739-78m8</guid>
    </item>
    <item>
      <title>gsd-2023-22648</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-22648</link>
      <description>gsd-2023-22648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-22648</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1340 — Rancher: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1340</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsvorkehrungen zu umgehen oder einen Cross Site Scripting angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsvorkehrungen zu umgehen oder einen Cross Site Scripting angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1340</guid>
    </item>
  </channel>
</rss>
