# CVE-2026-41053

## Summary

- **CVE ID:** CVE-2026-41053
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-303
- **Published:** Jun 30, 2026
- **Last Modified:** Jul 1, 2026

## Description

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

## Affected Products

- SUSE — Rancher (2.14.0)
- SUSE — Rancher (2.13.0)

## References

- [CNA](https://github.com/rancher/rancher/security/advisories/GHSA-4j6x-2764-m8gh)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.52%
- **EPSS Percentile:** 42.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._