<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:23:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329725</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329725</link>
      <description>EUVD-2026-329725</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329725</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44939</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44939</link>
      <description>&lt;p&gt;A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint  /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint  /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44939</guid>
    </item>
    <item>
      <title>GHSA-mhc6-2gfq-xx62 — Rancher vulnerable to command injection through unsanitized YAML parameter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mhc6-2gfq-xx62</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact
A critical command injection vulnerability has been identified in the Rancher Manager cluster import endpoint  `/v3/import/{token}_{clusterId}.yaml` through unsanitized YAML parameters. This endpoint accepts an `authImage` query parameter that is rendered without sanitization into a generated Kubernetes manifest template. By including URL-encoded newlines in the parameter value, an attacker can break out of the `image:` field to inject arbitrary YAML keys and malicious configurations, such as commands to execute malicious containers.&lt;/p&gt;
&lt;p&gt;Exploitation of this vulnerability requires the following conditions to be met:
- Attackers must obtain a valid cluster registration token (these tokens may be exposed, for example, through documentation, screenshots, or insecure communication channels).
- The victim’s cluster operator must execute `kubectl apply` against a maliciously crafted URL.&lt;/p&gt;
&lt;p&gt;When a victim applies this compromised manifest using `kubectl apply`, a DaemonSet is deployed with the injected configuration. This DaemonSet:
- Runs on all control-plane nodes with `hostNetwork: true` enabled.
- Uses the `cattle` service account, which possesses `cluster-admin` privileges.
- Mounts `/etc/kubernetes` directly from the host.
- Executes attacker-controlled commands via the injected `command:` field.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploits this vulnerability could:&lt;/p&gt;
&lt;p&gt;- Achieve full control over downstream Kubernetes clusters.
- Execute arbitrary code on control-plane nodes w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rancher/rancher&lt;/p&gt;
&lt;p&gt;### Impact
A critical command injection vulnerability has been identified in the Rancher Manager cluster import endpoint  `/v3/import/{token}_{clusterId}.yaml` through unsanitized YAML parameters. This endpoint accepts an `authImage` query parameter that is rendered without sanitization into a generated Kubernetes manifest template. By including URL-encoded newlines in the parameter value, an attacker can break out of the `image:` field to inject arbitrary YAML keys and malicious configurations, such as commands to execute malicious containers.&lt;/p&gt;
&lt;p&gt;Exploitation of this vulnerability requires the following conditions to be met:
- Attackers must obtain a valid cluster registration token (these tokens may be exposed, for example, through documentation, screenshots, or insecure communication channels).
- The victim’s cluster operator must execute `kubectl apply` against a maliciously crafted URL.&lt;/p&gt;
&lt;p&gt;When a victim applies this compromised manifest using `kubectl apply`, a DaemonSet is deployed with the injected configuration. This DaemonSet:
- Runs on all control-plane nodes with `hostNetwork: true` enabled.
- Uses the `cattle` service account, which possesses `cluster-admin` privileges.
- Mounts `/etc/kubernetes` directly from the host.
- Executes attacker-controlled commands via the injected `command:` field.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploits this vulnerability could:&lt;/p&gt;
&lt;p&gt;- Achieve full control over downstream Kubernetes clusters.
- Execute arbitrary code on control-plane nodes w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mhc6-2gfq-xx62</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1716 — Rancher: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Befehle zu injizieren und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Rancher ausnutzen, um seine Privilegien zu erhöhen, Befehle zu injizieren und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1716</guid>
    </item>
  </channel>
</rss>
