SUSE Vulnerabilities and Affected Products
Vulnerabilities associated with Rancher.
Products
Clear product- Rancher67 vulnerabilities
- SUSE Linux Enterprise Server 1513 vulnerabilities
- SUSE Linux Enterprise Server 1212 vulnerabilities
- openSUSE Tumbleweed11 vulnerabilities
- neuvector10 vulnerabilities
- SUSE Linux Enterprise Server for SAP 158 vulnerabilities
- libzypp7 vulnerabilities
- SUSE Linux Enterprise Server 15-LTSS7 vulnerabilities
- SUSE Manager Server Module 4.37 vulnerabilities
- open build service5 vulnerabilities
- openSUSE Factory5 vulnerabilities
- supportutils5 vulnerabilities
- SUSE Linux Enterprise Software Development Kit 12-SP45 vulnerabilities
- SUSE Linux Enterprise Software Development Kit 12-SP55 vulnerabilities
- SUSE Manager Server 4.25 vulnerabilities
- openSUSE Leap 15.54 vulnerabilities
- SUSE Linux Enterprise Server 114 vulnerabilities
- SUSE Linux Enterprise Server 11-SP4-LTSS4 vulnerabilities
- SUSE Linux Enterprise Server 12-SP54 vulnerabilities
- SUSE Linux Enterprise Server for SAP Applications 15 SP64 vulnerabilities
- SUSE Manager Server 4.04 vulnerabilities
- SUSE OpenStack Cloud 84 vulnerabilities
- harvester3 vulnerabilities
- opensuse_tumbleweed3 vulnerabilities
- SUSE Linux Enterprise High Performance Computing 15 SP53 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-44945CRITICAL | Cross-Cluster Impersonation Confused-Deputy Privilege EscalationA privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2. | CVSS9.1v3.1 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55998MEDIUM | Cluster Existence Oracle via Unauthenticated Import EndpointThe endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle. CWE-204Aug 5, 2026 | CVSS5.3v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59675HIGH | Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of ServiceWhen API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, the body-size cap (default 1 MiB) is bypassed for requests that pass through the audit copyReqBody path. An unauthenticated attacker can send arbitrarily large request bodies to the public login endpoints, causing the Rancher Manager server … CWE-770Aug 5, 2026 | CVSS7.5v3.1 | EPSS0.433% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-55996MEDIUM | Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agentA denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests. An unauthenticated attacker with network access within the affe… CWE-770Aug 5, 2026 | CVSS4.3v3.1 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44938HIGH | Fleet has PSS Bypass through addLabelsFromOptions in Fleet AgentA vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace. An attacker with git push access to a Fleet-monitored repository could overwrite Pod Security Standards (PSS) enforcement labels on a target namespace. This allows the attacker to weaken admission controls and deploy workloads that PSS policies would… CWE-522Jul 7, 2026 | CVSS8.8v3.1 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44937HIGH | SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL ComponentsPotential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system. | CVSS8.3v4.0 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44936MEDIUM | Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yamlMissing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 forwards Helm authentication credentials (BasicAuth) to any URL specified in the helm.repo field of a fleet.yaml file, allowing attackers able to push to fleet monitored git repos to leak helm access credentials. CWE-918Jul 6, 2026 | CVSS5.0v3.1 | EPSS0.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44934HIGH | Exposed tokens in SUSE Rancher AI Agent logsA information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials. CWE-215Jul 6, 2026 | CVSS7.0v4.0 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44935CRITICAL | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm DeployerMissing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants. | CVSS9.9v3.1 | EPSS0.412% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44948MEDIUM | Path Traversal in Rancher Fleet ImageScan GitRepo Path HandlerA path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service. CWE-23Jun 30, 2026 | CVSS5.3v4.0 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44949HIGH | Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookA Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook service could submit a crafted admission payload and cause workspace-related Kubernetes objects to be created with attacker-chosen identity data. CWE-306Jun 30, 2026 | CVSS7.0v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44947MEDIUM | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherA missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate. CWE-281Jun 30, 2026 | CVSS6.9v4.0 | EPSS0.229% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44946CRITICAL | SAML Authentication Replay in RancherA SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3, CWE-294Jun 30, 2026 | CVSS9.5v4.0 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41053HIGH | Over-inclusive team membership expansion in GitHub App authentication provider for RancherIncorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2. CWE-303Jun 30, 2026 | CVSS8.8v3.1 | EPSS0.454% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41052CRITICAL | Rancher Privilege Escalation from Project Owner to HostImproper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10. CWE-305Jun 29, 2026 | CVSS9.4v4.0 | EPSS0.414% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44939CRITICAL | Command injection through unsanitized YAML parameter in RancherA command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers. CWE-95Jun 19, 2026 | CVSS9.4v4.0 | EPSS1.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41050CRITICAL | Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template renderingFleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`. CWE-863May 13, 2026 | CVSS9.9v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25705HIGH | Rancher Extensions have arbitrary file access via path traversalA vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to: * Overwrite Rancher binaries or configuration to inject code. * Write to /var/lib/rancher/ to tamper with cluster state. * If hostPath volumes are mounted, wri… CWE-35May 13, 2026 | CVSS8.4v3.1 | EPSS0.369% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62879MEDIUM | Rancher Backup Operator pod's logs leak S3 tokensA vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. CWE-532Mar 4, 2026 | CVSS6.8v3.1 | EPSS0.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62878CRITICAL | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternA malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories. CWE-23Feb 25, 2026 | CVSS9.9v3.1 | EPSS0.581% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-67601HIGH | Rancher CLI skips TLS verification on Rancher CLI login commandA vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts. CWE-295Feb 25, 2026 | CVSS8.3v3.1 | EPSS0.153% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58269MEDIUM | Rancher exposes sensitive information through audit logsA vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs. CWE-532Oct 29, 2025 | CVSS4.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32199MEDIUM | Rancher user retains access to clusters despite Global Role removalA vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs CWE-281Oct 29, 2025 | CVSS4.3v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58260HIGH | Rancher update on users can deny the service to the adminA vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts. CWE-863Oct 2, 2025 | CVSS7.6v3.1 | EPSS0.453% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-58267HIGH | Rancher CLI SAML authentication is vulnerable to phishing attacksA vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens. CWE-345Oct 2, 2025 | CVSS8.0v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |