CVE-2026-71403
Last modified
CVE-2026-71403 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings. This issue affects Rancher: before 2.15.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Suse | Rancher | < 2.15.1 |
References
- https://github.com/rancher/rancher/pull/56616Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-71403?
How severe is CVE-2026-71403?
How do I fix CVE-2026-71403?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71396Bendix EC80 Brake ECU uses hard-coded credentials, which cou…5.4
- CVE-2026-71398Adobe Campaign Classic (ACC) is affected by an Incorrect Aut…10
- CVE-2026-71399Adobe XD is affected by a Buffer Overflow vulnerability that…7.8
- CVE-2026-7140A vulnerability has been found in Totolink A8000RU 7.1cu.643…9.8
- CVE-2026-71401An integer underflow was found in the DHCPv4 packet capture …5.3
- CVE-2026-71402An out-of-bounds read was found in the DHCPv4 packet capture…5.4
- CVE-2026-71404A flaw was found in Rancher Manager. The GlobalRole controll…8.7
- CVE-2026-71407A Stack-based Buffer Overflow vulnerability [CWE-121] vulner…8.1
- CVE-2026-71408A allocation of resources without limits or throttling vulne…5.3
- CVE-2026-7141A vulnerability was found in vLLM up to 0.19.0. The affected…5.6
- CVE-2026-71415Kirby is an open-source content management system. From 5.0.…7.1
- CVE-2026-71416Headroom compresses data before the data reaches a large lan…8.8
Are you affected by CVE-2026-71403?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
