CVE-2026-88804 - Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher
CVE ID :CVE-2026-88804 Published : Sept. 28, 2026, 3:58 p.m. | 17 minutes ago Description :An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before...