← Back to search

CVE-2026-55997

8.8 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows a malicious user to obtain long-lived registration tokens in plaintext, enabling them to register rogue nodes into the Rancher cluster at any time.
Exploitability
Exploitation is relatively easy given that tokens are stored in plaintext and can be accessed through various means such as the Rancher API, etcd, or direct file access.
Blast radius
If exploited, the impact could be severe, as it would allow unauthorized nodes to join the cluster, potentially leading to data breaches or unauthorized access.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the feature that generates long-lived registration tokens or upgrade to a version that addresses this vulnerability, such as 'Upgrade to 2.590 or later'.
auth-bypassapi-exploitplaintext-storagecluster-security

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-312

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.