CVE-2026-55997

HIGH

Long-lived Rancher registration token exposed in plaintext

Title source: cna
STIX 2.1

Description

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 0.2%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312
Status published
Products (2)
rancher/rancher 2.13.0 - 2.13.8
rancher/rancher 2.14.0 - 2.14.4
Published Aug 05, 2026
Tracked Since Aug 05, 2026