VendorsSUSErancherall versions
Vulnerabilities

SUSE Rancher

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2021-36782
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
Published 2022-09-07 · Modified
9.9EPSS 0.042
CVE-2023-22651
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected.
Published 2023-05-04 · Modified
9.9EPSS 0.008
CVE-2021-36783
Rancher: Failure to properly sanitize credentials in cluster template answers
Published 2022-09-07 · Modified
9.9EPSS 0.008
CVE-2023-22647
An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being preserved. When this operation was followed-up by other specially crafted commands, it could result in the user gaining access to tokens belonging to service accounts in the local cluster. This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.
Published 2023-06-01 · Modified
9.9EPSS 0.007
CVE-2022-43757
Rancher: Exposure of sensitive fields
Published 2023-02-07 · Modified
9.9EPSS 0.006
CVE-2022-43755
Rancher: Non-random authentication token
Published 2023-02-07 · Modified
9.8EPSS 0.017
CVE-2019-11202
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.
Published 2019-07-30 · Modified
9.8EPSS 0.016
CVE-2026-44946
SAML Authentication Replay in Rancher
Published 2026-06-30 · Analyzed
9.5EPSS 0.004
CVE-2026-41052
Rancher Privilege Escalation from Project Owner to Host
Published 2026-06-29 · Analyzed
9.4EPSS 0.004
CVE-2022-31247
Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Published 2022-09-07 · Modified
9.1EPSS 0.010
CVE-2018-20321
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against the k8s cluster. This could be mitigated by isolating the default namespace in a separate project, where only cluster admins can be given permissions to access. As of 2018-12-20, this bug affected ALL clusters created or imported by Rancher.
Published 2019-04-10 · Modified
9.0EPSS 0.018
CVE-2019-12303
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
Published 2019-06-06 · Modified
8.8EPSS 0.020
CVE-2017-7297
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.
Published 2017-03-29 · Modified
8.8EPSS 0.015
CVE-2019-12274
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml.
Published 2019-06-06 · Modified
8.8EPSS 0.011
CVE-2020-10676
In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.
Published 2023-12-12 · Modified
8.8EPSS 0.010
CVE-2022-43759
Rancher: Privilege escalation via promoted roles
Published 2023-02-07 · Modified
8.8EPSS 0.007
CVE-2026-41053
Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
Published 2026-06-30 · Analyzed
8.8EPSS 0.005
CVE-2022-21953
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
Published 2023-02-07 · Modified
8.8EPSS 0.005
CVE-2023-22648
A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in Rancher, even if they change groups on Azure AD, for example, to a lower privileged group, or are removed from a group, thus retaining their access to Rancher instead of losing it. This issue affects Rancher: from >= 2.6.7 before < 2.6.13, from >= 2.7.0 before < 2.7.4.
Published 2023-06-01 · Modified
8.8EPSS 0.005
CVE-2026-71404
Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole
Published 2026-09-03 · Analyzed
8.7EPSS 0.002
CVE-2023-22649
Rancher 'Audit Log' leaks sensitive information
Published 2024-10-16 · Analyzed
8.4EPSS 0.019
CVE-2022-43760
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victims. This could result in a user with write access to the affected areas being able to act on behalf of an administrator, once an administrator opens the affected web page. This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.
Published 2023-06-01 · Modified
8.4EPSS 0.007
CVE-2025-67601
Rancher CLI skips TLS verification on Rancher CLI login command
Published 2026-02-25 · Analyzed
8.3EPSS 0.002
CVE-2019-6287
In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in a project after they have been removed from it.
Published 2019-04-10 · Modified
8.1EPSS 0.010
CVE-2026-75033
Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
Published 2026-09-03 · Analyzed
7.7EPSS 0.002
CVE-2026-75035
Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass
Published 2026-09-03 · Analyzed
7.7EPSS 0.002
CVE-2022-43758
Rancher: Command injection in Git package
Published 2023-02-07 · Modified
7.6EPSS 0.010
CVE-2021-36778
Exposure of repository credentials to external third-party sources
Published 2022-05-02 · Modified
7.5EPSS 0.008
CVE-2026-75034
Rancher: SAML Assertion Replay
Published 2026-09-03 · Analyzed
7.4EPSS 0.002
CVE-2021-36784
Privilege escalation for users with create/update permissions in Global Roles
Published 2022-05-02 · Modified
7.2EPSS 0.009
CVE-2021-25313
Rancher: XSS on /v3/cluster/
Published 2021-03-05 · Modified
7.1EPSS 0.015
CVE-2022-21951
Rancher: Weave CNI password is not set if RKE template is used with CNI value overridden
Published 2022-05-25 · Modified
6.8EPSS 0.004
CVE-2019-13209
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.
Published 2019-09-04 · Modified
6.1EPSS 0.011
CVE-2026-71403
Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind
Published 2026-09-03 · Analyzed
6.1EPSS 0.002
CVE-2021-4200
Write access to the Catalog for any user when restricted-admin role is enabled
Published 2022-05-02 · Modified
5.5EPSS 0.006
CVE-2019-11881
A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading" message.
Published 2019-06-10 · Modified
4.7EPSS 0.023