SUSE Linux security advisory (AV26-974)
Canadian Cyber Centre relayed SUSE advisory AV26-974 covering Rancher flaws including stored XSS, session issues, and cross-tenant secret disclosure; patches advised.
The Canadian Centre for Cyber Security issued advisory AV26-974 for SUSE Rancher vulnerabilities affecting numerous versions across release lines up to 2.15.2. The flaws include unauthenticated update of public UI settings leading to stored cross-site scripting, sessions not revoked server-side on logout, Fleet agent copying downstream resources with cluster-admin privileges allowing cross-namespace writes, and cross-tenant BundleDeployment and Secret disclosure via spoofed cluster labels during agent-initiated registration. Users and administrators are urged to apply updates as they become available.