VulnSea

rancher vulnerabilities

CVEs whose affected-version data names the rancher package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-75034High· 7.4
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. I…

Twilightsuse · rancherEPSS 0.20%via NVD
CVE-2026-75033High· 7.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user…

Twilightsuse · rancherEPSS 0.21%via NVD
CVE-2026-71404High· 8.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A us…

Twilightsuse · rancherEPSS 0.24%via NVD
CVE-2026-71403Medium· 6.1
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user holding the `update` verb on `users.management.cattle.io` could inject a foreig…

Sunlitsuse · rancherEPSS 0.21%via NVD
CVE-2026-75035High· 7.7
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authent…

Twilightsuse · rancherEPSS 0.20%via NVD
rancher vulnerabilities (CVEs) · VulnSea