CVE-2026-71403 MEDIUM

CVE-2026-71403: Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind

Vendor Suse
Product Rancher
Weakness CWE-639 · IDOR
Published September 3, 2026
Last update September 4, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreign identity provider principal into any account, so that the next login by the owner of that principal was bound to the victim's account and inherited its role bindings. This issue affects Rancher: before 2.15.1.

Key dates

02Disclosure timeline

September 3, 2026 CVE published
September 4, 2026 Record updated

Related vulnerabilities

04Related CVE