Suse Rancher vulnerabilities
72 known vulnerabilities affecting suse/rancher.
Total CVEs
72
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH37MEDIUM21
Vulnerabilities
Page 1 of 4
CVE-2021-36782P2CRITICALCVSS 9.9PoC≥ 2.5.0, < 2.5.16≥ 2.6.0, < 2.6.7+2 more2022-09-07
CVE-2021-36782 [CRITICAL] CWE-312 CVE-2021-36782: A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Clus
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE Rancher Rancher versions prior to 2.5.16; Rancher versions prior to 2.6.7.
nvd
CVE-2022-31249P2CRITICALCVSS 9.8≥ wrangler, ≤ 0.7.32023-02-07
CVE-2022-31249 [CRITICAL] CWE-78 CVE-2022-31249: A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnera
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote attackers to inject commands in the underlying host via crafted commands passed to Wrangler. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler version 0.8.4 and prior
nvd
CVE-2026-44939P2CRITICALCVSS 9.4≥ 2.14.0, < 2.14.2≥ 2.13.0, < 2.13.6+3 more2026-06-19
CVE-2026-44939 [CRITICAL] CWE-95 CVE-2026-44939: A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
nvd
CVE-2023-22649P3MEDIUMCVSS 6.5PoC≥ 2.6.0, < 2.6.14≥ 2.7.0, < 2.7.10+1 more2024-10-16
CVE-2023-22649 [MEDIUM] CWE-532 CVE-2023-22649: A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's aud
A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log) is an opt-in feature, only deployments that have it enabled and have [AUDIT_LEVEL](https://ranchermanager.docs.rancher.co
nvd
CVE-2021-36783P2CRITICALCVSS 9.9≥ 2.5.0, < 2.5.13≥ 2.6.0, < 2.6.4+2 more2022-09-07
CVE-2021-36783 [CRITICAL] CWE-522 CVE-2021-36783: A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Ow
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versi
nvd
CVE-2025-62878P3CRITICALCVSS 9.9fixed in 0.0.342026-02-25
CVE-2025-62878 [CRITICAL] CWE-23 CVE-2025-62878: A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.
nvd
CVE-2026-44935P2CRITICALCVSS 9.9≥ 0.15.0, < 0.15.2≥ 0.14.0, < 0.14.6+2 more2026-07-02
CVE-2026-44935 [CRITICAL] CWE-1287 CVE-2026-44935: Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.1
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
nvd
CVE-2026-41053P2HIGHCVSS 8.8≥ 2.13.0, < 2.13.6≥ 2.14.0, < 2.14.22026-06-30
CVE-2026-41053 [HIGH] CWE-303 CVE-2026-41053: Incorrect authentication caching in the team member ship expansion of the Rancher Github authenticat
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.
nvd
CVE-2022-43755P3CRITICALCVSS 9.8≥ 2.6.0, < 2.6.10≥ 2.7.0, < 2.7.1+1 more2023-02-07
CVE-2022-43755 [CRITICAL] CWE-331 CVE-2022-43755: A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the c
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
nvd
CVE-2026-44938P2HIGHCVSS 8.8≥ 0.15.0, < 0.15.2≥ 0.14.0, < 0.14.6+2 more2026-07-07
CVE-2026-44938 [HIGH] CWE-522 CVE-2026-44938: A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-se
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace.
An attacker with git push access to a
Fleet-monitored repository could overwrite Pod Security Standards (PSS
nvd
CVE-2019-11202P3CRITICALCVSS 9.8≥ 2.0.0, ≤ 2.0.13≥ 2.1.0, ≤ 2.1.8+1 more2019-07-30
CVE-2019-11202 [CRITICAL] CWE-287 CVE-2019-11202: An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher
nvd
CVE-2026-41050P3CRITICALCVSS 9.9≥ 0.15.0, < 0.15.1≥ 0.14.0, < 0.14.5+3 more2026-05-13
CVE-2026-41050 [CRITICAL] CWE-863 CVE-2026-41050: Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
nvd
CVE-2023-22651P3CRITICALCVSS 9.9≥ 2.6.0, ≤ 2.7.22023-05-04
CVE-2023-22651 [CRITICAL] CWE-269 CVE-2023-22651: Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure i
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to
the misconfiguration of the Webhook. This component enforces validation
rules and security checks before resources are admitted into the
Kubernetes cluster.
The issue only affects users t
nvd
CVE-2018-20321P3HIGHCVSS 8.8≥ 2.0.0, ≤ 2.1.52019-04-10
CVE-2018-20321 [HIGH] CWE-668 CVE-2018-20321: An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default na
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. This could be mitigated by isolating the default namespace in a separate project, where only clust
nvd
CVE-2019-12303P3HIGHCVSS 8.8≥ 2.0.0, ≤ 2.2.32019-06-06
CVE-2019-12303 [HIGH] CWE-74 CVE-2019-12303: In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
nvd
CVE-2024-22036P3CRITICALCVSS 9.1≥ 2.7.0, < 2.7.16≥ 2.8.0, < 2.8.9+1 more2025-04-16
CVE-2024-22036 [CRITICAL] CWE-269 CVE-2024-22036: A vulnerability has been identified within Rancher where a cluster or node driver can be used to esc
A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot
jail and gain root access to the Rancher container itself. In
production environments, further privilege escalation is possible based
on living off the land within the Rancher container itself. For the test
and development environment
nvd
CVE-2025-23391P3CRITICALCVSS 9.1≥ 2.8.0, < 2.8.14≥ 2.9.0, < 2.9.8+1 more2025-04-11
CVE-2025-23391 [CRITICAL] CWE-266 CVE-2025-23391: A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts.
This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.
nvd
CVE-2023-22650P3HIGHCVSS 8.8≥ 2.7.0, < 2.7.14≥ 2.8.0, < 2.8.52024-10-16
CVE-2023-22650 [HIGH] CWE-287 CVE-2023-22650: A vulnerability has been identified in which Rancher does not automatically clean up a user which ha
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which may leave the user’s tokens still usable.
nvd
CVE-2026-41052P3HIGHCVSS 8.8≥ 2.12.0, < 2.12.10≥ 2.13.0, < 2.13.6+1 more2026-06-29
CVE-2026-41052 [HIGH] CWE-305 CVE-2026-41052: Improper privilege handling could be used by users with Project Owner role to escalate privileges, i
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
nvd
CVE-2021-36776P3HIGHCVSS 8.8≥ Rancher, < 2.5.102022-04-04
CVE-2021-36776 [HIGH] CWE-284 CVE-2021-36776: A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrar
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.
nvd
1 / 4Next →