CVE-2026-88805
Received Received - Intake

Incorrect Credential Retention in SUSE Rancher

Vulnerability report for CVE-2026-88805, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: SUSE

Description

Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
suse rancher to 2.15.2 (exc)
suse rancher From 2.15.0 (inc) to 2.15.2 (exc)
suse rancher 2.15.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves incorrect credential cleaning during logout in SUSE Rancher 2.15 before version 2.15.2. When a user logs out, browser session cookies are cleared but the server-side session token remains valid. This allows attackers who obtain a valid session token before logout to retain access with the victim's identity and permissions until the token expires.

Detection Guidance

To detect this vulnerability, check for active session tokens in Rancher's backing store after logout. Inspect logs for API requests using tokens that should have been revoked. Look for unauthorized access attempts using stale session tokens. Review Rancher version to confirm if it is >=v2.15.0 and <v2.15.2.

Impact Analysis

An attacker could gain unauthorized access to your Rancher account and perform actions with your permissions. This includes accessing sensitive data, modifying configurations, or performing administrative tasks if the session token has elevated privileges. The impact depends on the permissions associated with the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements such as GDPR's data protection principles or HIPAA's access controls. Organizations using affected Rancher versions may face compliance violations if unauthorized access occurs, potentially resulting in legal or financial penalties.

Mitigation Strategies

Immediately upgrade Rancher to version 2.15.2 or later to apply the fix. As a temporary workaround, reduce session token time-to-live settings or manually delete active session tokens from the backing store. Ensure all authentication providers (OIDC-based) are updated and configured correctly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88805. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart