CVE-2026-88804EPSS p43.3%
CVE-2026-88804CVE-2026-88804
Description
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Scoring
| CVSS | 9.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
| EPSS | 0.54% probability of exploitation · percentile 43.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |