SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71403

MEDIUM · CVSS 6.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Rancher Manager allows users with update permissions on user resources to modify the `username` and `principalIds` fields, potentially injecting foreign identity provider principals into accounts. This could lead to unauthorized access, as the legitimate user’s next login would be redirected to the attacker's account, inheriting their role bindings. Organizations using Rancher versions prior to 2.15.1 should prioritize patching this issue to mitigate the risk of account takeover.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71403
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%

Original NVD Description

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings. This issue affects Rancher: before 2.15.1.