VulnSea

github.com/rancher/rancher vulnerabilities

CVEs whose affected-version data names the github.com/rancher/rancher package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

23 CVEsRSS

CVE-2026-44939Critical· 9.6
2mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-41053High· 8.8
2mo ago

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Twilightrancher · github.com/rancher/rancherEPSS 0.52%via OSV
CVE-2026-41052Critical· 8.4
2mo ago

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

Midnightrancher · github.com/rancher/rancherEPSS 0.42%via GHSA
CVE-2026-25705High· 8.4
4mo ago

Rancher Extensions have arbitrary file access via path traversal

Rancher Extensions have arbitrary file access via path traversal

Twilightrancher · github.com/rancher/rancherEPSS 0.37%via OSV
CVE-2021-25320Critical· 9.9
6mo ago

Rancher cloud credentials can be used through proxy API by users without access

Rancher cloud credentials can be used through proxy API by users without access

Midnightrancher · github.com/rancher/rancherEPSS 0.85%via OSV
CVE-2022-21951Medium· 6.8
6mo ago

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Sunlitrancher · github.com/rancher/rancherEPSS 0.39%via OSV
CVE-2023-22648High· 8.0
6mo ago

Rancher's Azure AD permission changes are not reflected on active sessions

Rancher's Azure AD permission changes are not reflected on active sessions

Twilightrancher · github.com/rancher/rancherEPSS 0.45%via OSV
CVE-2021-36783Critical· 9.9
6mo ago

Rancher doesn't properly sanitize credentials in cluster template answers

Rancher doesn't properly sanitize credentials in cluster template answers

Midnightrancher · github.com/rancher/rancherEPSS 0.76%via OSV
CVE-2022-31247Critical· 9.1
6mo ago

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Midnightrancher · github.com/rancher/rancherEPSS 0.96%via OSV
CVE-2025-23387Medium· 5.3
1y ago

Rancher's SAML-based login via CLI can be denied by unauthenticated users

Rancher's SAML-based login via CLI can be denied by unauthenticated users

Sunlitrancher · github.com/rancher/rancherEPSS 0.58%via OSV
CVE-2024-52281High· 8.9
1y ago

Rancher UI has Stored Cross-site Scripting vulnerability

Rancher UI has Stored Cross-site Scripting vulnerability

Twilightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2023-32196Critical· 9.1
1y ago

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Midnightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2021-36775High· 8.0
2y ago

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Twilightrancher · github.com/rancher/rancherEPSS 0.97%via OSV
CVE-2021-31999High· 8.8
2y ago

Rancher Privilege escalation vulnerability via malicious "Connection" header

Rancher Privilege escalation vulnerability via malicious "Connection" header

Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2021-25318High· 8.8
2y ago

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2023-22647Critical· 9.9
3y ago

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Midnightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2020-10676High· 8.8
3y ago

Rancher users retain access after moving namespaces into projects they don't have access to

Rancher users retain access after moving namespaces into projects they don't have access to

Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2022-43760High· 8.4
3y ago

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Twilightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-22651Critical· 9.9
3y ago

Rancher Webhook is misconfigured during upgrade process

Rancher Webhook is misconfigured during upgrade process

Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2021-36782Critical· 9.9PoC
4y ago

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Abyssalrancher · github.com/rancher/rancherEPSS 4.2%via OSV
CVE-2019-12274High· 8.8
4y ago

Rancher Privilege Escalation Vulnerability

Rancher Privilege Escalation Vulnerability

Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2021-25313Medium· 6.1
4y ago

Rancher Cross-site Scripting Vulnerability

Rancher Cross-site Scripting Vulnerability

Sunlitrancher · github.com/rancher/rancherEPSS 1.5%via OSV
GHSA-wm2r-rp98-8pmhLow
4y ago

Exposure of SSH credentials in Rancher/Fleet

Exposure of SSH credentials in Rancher/Fleet

Sunlitrancher · github.com/rancher/ranchervia OSV
github.com/rancher/rancher vulnerabilities (CVEs) · VulnSea