Suse Rancher vulnerabilities
72 known vulnerabilities affecting suse/rancher.
Total CVEs
72
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH37MEDIUM21
Vulnerabilities
Page 2 of 4
CVE-2022-43759P3HIGHCVSS 8.8≥ 2.5.0, < 2.5.17≥ 2.6.0, < 2.6.10+2 more2023-02-07
CVE-2022-43759 [HIGH] CWE-269 CVE-2022-43759: A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escal
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10.
nvd
CVE-2022-21953P3HIGHCVSS 8.8≥ 2.5.0, < 2.5.17≥ 2.6.0, < 2.6.10+2 more2023-02-07
CVE-2022-21953 [HIGH] CWE-862 CVE-2022-21953: A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unau
A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the local cluster This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
nvd
CVE-2020-10676P3HIGHCVSS 8.8≥ 2.0.0, < 2.6.13≥ 2.7.0, < 2.7.42023-12-12
CVE-2020-10676 [HIGH] CWE-863 CVE-2020-10676: In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allo
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
nvd
CVE-2021-36775P3HIGHCVSS 8.8≥ Rancher, < 2.4.18≥ Rancher, < 2.5.12+1 more2022-04-04
CVE-2021-36775 [HIGH] CWE-284 CVE-2021-36775: a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should
a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.
nvd
CVE-2025-23389P3HIGHCVSS 8.4≥ 2.8.0, < 2.8.13≥ 2.9.0, < 2.9.7+1 more2025-04-11
CVE-2025-23389 [HIGH] CWE-284 CVE-2025-23389: A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other ide
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login.
This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
nvd
CVE-2022-45157P3CRITICALCVSS 9.1≥ 2.9.0, < 2.9.3≥ 2.7.0, < 2.8.92024-11-13
CVE-2022-45157 [CRITICAL] CWE-522 CVE-2022-45157: A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Int
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside Rancher. This vulnerability is only
nvd
CVE-2022-43757P3HIGHCVSS 8.8≥ 2.5.0, < 2.5.17≥ 2.6.0, < 2.6.10+2 more2023-02-07
CVE-2022-43757 [HIGH] CWE-312 CVE-2022-43757: A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed c
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
nvd
CVE-2023-22648P3HIGHCVSS 8.8≥ 2.6.7, < 2.6.13≥ 2.7.0, < 2.7.4+2 more2023-06-01
CVE-2023-22648 [HIGH] CWE-271 CVE-2023-22648: A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD
A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users
while they are logged in the Rancher UI. This would cause the users to
retain their previous permissions in Rancher, even if they change groups
on Azure AD, for example, to a lower privileged group, or are removed
from a grou
nvd
CVE-2017-7297P3HIGHCVSS 8.8≥ 1.2.0, < 1.2.4≥ 1.3.0, < 1.3.5+2 more2017-03-29
CVE-2017-7297 [HIGH] CVE-2017-7297: Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.
nvd
CVE-2024-58267P3HIGHCVSS 8.0≥ 2.12.0, < 2.12.2≥ 2.11.0, < 2.11.6+2 more2025-10-02
CVE-2024-58267 [HIGH] CWE-345 CVE-2024-58267: A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.
nvd
CVE-2024-58259P3HIGHCVSS 8.2≥ 2.12.0, < 2.12.1≥ 2.11.0, < 2.11.5+3 more2025-09-02
CVE-2024-58259 [HIGH] CWE-770 CVE-2024-58259: A vulnerability has been identified within Rancher Manager in which it did not enforce request body
A vulnerability has been identified within Rancher Manager in which it
did not enforce request body size limits on certain public
(unauthenticated) and authenticated API endpoints. This allows a
malicious user to exploit this by sending excessively large payloads,
which are fully loaded into memory during processing, leading to Denial of Service (DoS).
nvd
CVE-2019-12274P3HIGHCVSS 8.8≥ 1.0.0, ≤ 1.6.28≥ 2.0.0, ≤ 2.2.32019-06-06
CVE-2019-12274 [HIGH] CWE-668 CVE-2019-12274: In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin acc
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/
nvd
CVE-2022-21947P3HIGHCVSS 8.8≥ Desktop, < V2022-04-01
CVE-2022-21947 [HIGH] CWE-668 CVE-2022-21947: A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in
A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.
nvd
CVE-2025-23388P3HIGHCVSS 8.2≥ 2.8.0, < 2.8.13≥ 2.9.0, < 2.9.7+1 more2025-04-11
CVE-2025-23388 [HIGH] CWE-121 CVE-2025-23388: A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue
A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
nvd
CVE-2026-44937P3HIGHCVSS 8.2≥ 0.15.0, < 0.15.2≥ 0.14.0, < 0.14.6+2 more2026-07-06
CVE-2026-44937 [HIGH] CWE-918 CVE-2026-44937: Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.1
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5 could be used by remote attackers to cause a denial of service or a downgrade attack on other repositories on the system.
nvd
CVE-2022-31247P3CRITICALCVSS 9.1≥ 2.5.0, < 2.5.16≥ 2.6.0, < 2.6.7+2 more2022-09-07
CVE-2022-31247 [CRITICAL] CWE-285 CVE-2022-31247: An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to crea
An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another project in the same cluster or in another project
nvd
CVE-2026-44946P3HIGHCVSS 7.4≥ 2.11.0, < 2.11.15≥ 2.12.0, < 2.12.11+2 more2026-06-30
CVE-2026-44946 [HIGH] CWE-294 CVE-2026-44946: A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler di
A SAML authentication replay vulnerability in Rancher's Assertion
Consumer Service (ACS) handler did not enforce
one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
nvd
CVE-2026-25705P3HIGHCVSS 8.4≥ 2.14.0, < 2.14.1≥ 2.13.0, < 2.13.5+2 more2026-05-13
CVE-2026-25705 [HIGH] CWE-35 CVE-2026-25705: A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.co
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to: * Overwrite Rancher bin
nvd
CVE-2021-36778P3HIGHCVSS 7.5fixed in 2.5.12≥ 2.6.0, < 2.6.3+2 more2022-05-02
CVE-2021-36778 [HIGH] CWE-863 CVE-2021-36778: A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party reposit
A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.
nvd
CVE-2024-52281P3HIGHCVSS 8.9≥ 2.9.0, < 2.9.42025-04-16
CVE-2024-52281 [HIGH] CWE-79 CVE-2024-52281: A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows
A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to perform a Stored XSS attack through the cluster description field.
This issue affects rancher: from 2.9.0 before 2.9.4.
nvd