Skip to main content

Vendor/product archive

suse / rancher CVEs

Beta · best-effort

31 CVEs tagged to suse / rancher9 Critical, 18 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-44946

Published Jun 30, 2026

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in t…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41053

Published Jun 30, 2026

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41052

Published Jun 29, 2026

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67601

Published Feb 25, 2026

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22649

Published Oct 16, 2024

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10676

Published Dec 12, 2023

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a dif…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22648

Published Jun 1, 2023

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This wou…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22647

Published Jun 1, 2023

An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43760

Published Jun 1, 2023

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject co…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22651

Published May 4, 2023

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfigura…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43759

Published Feb 7, 2023

A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any clu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43758

Published Feb 7, 2023

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43757

Published Feb 7, 2023

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials ex…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43755

Published Feb 7, 2023

A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This iss…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21953

Published Feb 7, 2023

A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects:…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31247

Published Sep 7, 2022

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36783

Published Sep 7, 2022

A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials,…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36782

Published Sep 7, 2022

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to u…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-21951

Published May 25, 2022

A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4200

Published May 2, 2022

A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Ranch…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36784

Published May 2, 2022

A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36778

Published May 2, 2022

A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects:…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25313

Published Mar 5, 2021

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13209

Published Sep 4, 2019

Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a vict…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11202

Published Jul 30, 2019

An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2