{"id":"CVE-2026-55997","published":"2026-08-05T08:16:34.330","lastModified":"2026-08-06T05:17:04.460","description":"Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-312"],"vendors":[],"products":[],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55997","tags":[]},{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4","tags":[]}],"exploitRefs":[{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a malicious user to obtain long-lived registration tokens in plaintext, enabling them to register rogue nodes into the Rancher cluster at any time.","exploitability":"Exploitation is relatively easy given that tokens are stored in plaintext and can be accessed through various means such as the Rancher API, etcd, or direct file access.","blast_radius":"If exploited, the impact could be severe, as it would allow unauthorized nodes to join the cluster, potentially leading to data breaches or unauthorized access.","remediation":"Disable the feature that generates long-lived registration tokens or upgrade to a version that addresses this vulnerability, such as 'Upgrade to 2.590 or later'.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","api-exploit","plaintext-storage","cluster-security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:20:03.597Z"}}