PatchSiren

Rancher CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH rancher CVE published 2026-08-05

CVE-2026-55997

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T08:16:34.330Z and has not been modified since then. CVE-2026-55997 is a vulnerability in Rancher that issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens are stored and exposed in plaintext with no expiration, allowing a malicious user [truncated]

HIGH rancher CVE published 2026-05-28

CVE-2026-44543

A high-severity vulnerability in Rancher Local Path Provisioner versions prior to 0.0.36 allows privilege escalation through ConfigMap template manipulation. The provisioner's helperPod.yaml template, stored in the local-path-config ConfigMap within the local-path-storage namespace, lacks sufficient validation before use during PVC provisioning and cleanup operations. An attacker with permissions to edit [truncated]