VulnSea

Rancher vulnerabilities

CVEs whose affected-version data names the Rancher package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-88805High· 8.1
today

Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out

Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.

▾ TwilightSUSE · Ranchervia NVD
CVE-2026-88804Critical· 9.6
today

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before…

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before…

▾ MidnightSUSE · Ranchervia NVD
CVE-2026-75034High· 7.4
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. I…

▾ Twilightsuse · rancherEPSS 0.32%via NVD
CVE-2026-75033High· 7.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user…

▾ Twilightsuse · rancherEPSS 0.34%via NVD
CVE-2026-71404High· 8.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A us…

▾ Twilightsuse · rancherEPSS 0.42%via NVD
CVE-2026-71403Medium· 6.1
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreig…

▾ Sunlitsuse · rancherEPSS 0.37%via NVD
CVE-2026-75035High· 7.7
3w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authent…

▾ Twilightsuse · rancherEPSS 0.34%via NVD
Rancher vulnerabilities (CVEs) · VulnSea