
CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating 🔥 An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters. 👉 https://nt.ls/dtxM5

