OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-88804

CRITICAL · CVSS 9.6 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows remote attackers to exploit unauthenticated updates of public UI settings in the Rancher UI, leading to stored cross-site scripting (XSS) attacks. This can compromise the integrity of the application and potentially allow attackers to execute malicious scripts in the context of a user's session. Organizations using affected versions of SUSE Rancher should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88804
Severity
CRITICAL
CVSS
9.6
EPSS
0.54%

Original NVD Description

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.