CVE-2026-88805: Session Not Revoked Server-Side on Logout in Rancher
Published Sep 28, 2026
·Updated
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
Affected Software
1 affected component
SUSE rancher<2.15.2
Event History
Sep 28, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Rancher deployments are affected?
SUSE Rancher 2.15 versions before 2.15.2 are affected.
2
What does an attacker need to exploit this issue?
The issue is remotely exploitable with low attack complexity and no attacker privileges, but it requires user interaction. The attacker must retain access credentials that remain valid after the associated account logs out.
3
What is the practical impact of successful exploitation?
An attacker can continue using retained credentials after logout, potentially gaining high-impact access to confidentiality and integrity. Availability impact is not indicated.