Incorrect Implementation of Authentication Algorithm Affecting github.com/rancher/rancher/pkg/auth/providers/github package, versions >=2.13.0-alpha1 <2.13.6-alpha5>=2.14.0-alpha1 <2.14.2-alpha5>=2.15.0-alpha1 <2.15.0-alpha5


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.52% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMRANCHERRANCHERPKGAUTHPROVIDERSGITHUB-17808305
  • published3 Jul 2026
  • disclosed1 Jul 2026
  • creditUnknown

Introduced: 1 Jul 2026

CVE-2026-41053  (opens in a new tab)
CWE-303  (opens in a new tab)

How to fix?

Upgrade github.com/rancher/rancher/pkg/auth/providers/github to version 2.13.6-alpha5, 2.14.2-alpha5, 2.15.0-alpha5 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm in the authentication provider's team membership evaluation process. An attacker can gain unauthorized access to resources or permissions assigned to other teams within the same organization by authenticating with a valid account that is a member of any team in the organization. This is only exploitable if the GitHub App authentication provider is enabled and configured for the target organization, the attacker is a member of at least one team, and another team is explicitly mapped to RBAC roles or allowlists.

Workaround

This vulnerability can be mitigated by disabling the GitHub App authentication provider, switching to an alternative authentication provider (such as GitHub OAuth), removing or restricting team-based group principals from allowed principalIds, auditing and temporarily removing RBAC bindings that reference GitHub App team principals, or disabling provider refresh and cleaning up inflated group membership for users.

CVSS Base Scores

version 4.0
version 3.1