SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71404

HIGH · CVSS 8.7 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in Rancher Manager allows users with delegated GlobalRole create or update permissions to manipulate the `authz.management.cattle.io/cr-name` annotation, enabling them to overwrite the rules of existing ClusterRoles, including critical ones like `cluster-admin`. This can lead to unauthorized revocation of permissions for all principals associated with the affected ClusterRole, with the changes persisting even after the malicious role is removed. Organizations using Rancher versions prior to 2.15.1 should prioritize patching this high-severity vulnerability to mitigate potential privilege escalation and access control issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71404
Severity
HIGH
CVSS
8.7
EPSS
0.25%

Original NVD Description

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.