CVE-2021-36775High· 8.0▾ TwilightRancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.9%
0.9% → 1.0%
Last analysed / modified upstream
This vulnerability only affects customers using group based authentication in Rancher versions up to and including 2.4.17, 2.5.11 and 2.6.2.
When removing a Project Role associated to a group from a project, the bindings that grant access to cluster scoped resources for those subjects do not get deleted. This happens due to an incomplete authorization logic check. A user who is a member of an affected group with authenticated access to Rancher could use this to access resources they should no longer have access to. The exposure level will depend on the original permission level granted to the affected project role.
Patched versions include releases 2.4.18, 2.5.12, 2.6.3 and later versions.
Limit access in Rancher to trusted users. There is not a direct mitigation besides upgrading to the patched Rancher versions.
Cluster and project roles documentation for Rancher 2.6, 2.5 and 2.4.
If you have any questions or comments about this advisory:
github.com/rancher/rancher < 2.4.18github.com/rancher/rancher >= 2.5.0, < 2.5.12github.com/rancher/rancher >= 2.6.0, < 2.6.3Upgrade to a patched release:
github.com/rancher/rancher 2.4.18github.com/rancher/rancher 2.5.12github.com/rancher/rancher 2.6.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header