CVE-2022-43760High· 8.4▾ TwilightRancher UI has multiple Cross-Site Scripting (XSS) issues
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in the Rancher UI. Cross-Site scripting allows a malicious user to inject code that is executed within another user's browser, allowing the attacker to steal sensitive information, manipulate web content, or perform other malicious activities on behalf of the victims. This could result in a user with write access to the affected areas being able to act on behalf of an administrator, once an administrator opens the affected web page.
The affected areas include the Projects/Namespaces and Auth Provider sections. The attacker needs to be authenticated and have write access to those features in order to exploit the vulnerabilities. Some of the permissions (roles) required are:
For users that suspect this vulnerability may have targeted their Rancher instance, we recommend rotating all API Keys and Kubeconfig tokens.
It's also advised to review logs and possibly rotate credentials stored as secrets in Rancher and downstream cluster, if you believe that users' credentials to access Rancher and its clusters might have been compromised.
Patched versions include releases 2.6.13, 2.7.4 and later versions.
There is no direct mitigation besides updating Rancher to a patched version.
We would like to recognize and thank @bybit-sec for the responsible disclosure of this security issue.
If you have any questions or comments about this advisory:
github.com/rancher/rancher >= 2.6.0, < 2.6.13github.com/rancher/rancher >= 2.7.0, < 2.7.4Upgrade to a patched release:
github.com/rancher/rancher 2.6.13github.com/rancher/rancher 2.7.4Connected by shared product, vendor, weakness, or advisory.
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability