VulnSea

rancher has 28 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 7 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 8.8 (high), with 10 rated critical. None have a confirmed exploitation report. Most affected products: github.com/rancher/rancher (23), github.com/rancher/fleet (4), github.com/rancher/apiserver (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
7 prev 1

Products

  • github.com/rancher/rancher 23
  • github.com/rancher/fleet 4
  • github.com/rancher/apiserver 1
28
Total CVEs
10
Critical
0
CISA KEV
0
Exploited

rancher vulnerabilities

CVEs affecting rancher, newest first. Open any entry for full detail, references, and exploit status.

28 CVEsRSS

CVE-2026-44938High· 8.8
2mo ago

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Twilightrancher · github.com/rancher/fleetEPSS 0.44%via GHSA
CVE-2026-44937High· 7.5
2mo ago

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Twilightrancher · github.com/rancher/fleetEPSS 0.42%via GHSA
CVE-2026-44939Critical· 9.6
2mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-44936Medium· 5.0
2mo ago

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

Sunlitrancher · github.com/rancher/fleetEPSS 0.35%via GHSA
CVE-2026-44935Critical· 9.9
2mo ago

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Midnightrancher · github.com/rancher/fleetEPSS 0.49%via GHSA
CVE-2026-41053High· 8.8
2mo ago

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Twilightrancher · github.com/rancher/rancherEPSS 0.52%via OSV
CVE-2026-41052Critical· 8.4
2mo ago

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

Midnightrancher · github.com/rancher/rancherEPSS 0.42%via GHSA
CVE-2026-25705High· 8.4
4mo ago

Rancher Extensions have arbitrary file access via path traversal

Rancher Extensions have arbitrary file access via path traversal

Twilightrancher · github.com/rancher/rancherEPSS 0.37%via OSV
CVE-2021-25320Critical· 9.9
6mo ago

Rancher cloud credentials can be used through proxy API by users without access

Rancher cloud credentials can be used through proxy API by users without access

Midnightrancher · github.com/rancher/rancherEPSS 0.85%via OSV
CVE-2022-21951Medium· 6.8
6mo ago

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Rancher's weave CNI password is not configured when a cluster is created from an RKE template

Sunlitrancher · github.com/rancher/rancherEPSS 0.39%via OSV
CVE-2023-22648High· 8.0
6mo ago

Rancher's Azure AD permission changes are not reflected on active sessions

Rancher's Azure AD permission changes are not reflected on active sessions

Twilightrancher · github.com/rancher/rancherEPSS 0.45%via OSV
CVE-2021-36783Critical· 9.9
6mo ago

Rancher doesn't properly sanitize credentials in cluster template answers

Rancher doesn't properly sanitize credentials in cluster template answers

Midnightrancher · github.com/rancher/rancherEPSS 0.76%via OSV
CVE-2022-31247Critical· 9.1
6mo ago

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)

Midnightrancher · github.com/rancher/rancherEPSS 0.96%via OSV
CVE-2025-23387Medium· 5.3
1y ago

Rancher's SAML-based login via CLI can be denied by unauthenticated users

Rancher's SAML-based login via CLI can be denied by unauthenticated users

Sunlitrancher · github.com/rancher/rancherEPSS 0.58%via OSV
CVE-2024-52281High· 8.9
1y ago

Rancher UI has Stored Cross-site Scripting vulnerability

Rancher UI has Stored Cross-site Scripting vulnerability

Twilightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2023-32196Critical· 9.1
1y ago

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists

Midnightrancher · github.com/rancher/rancherEPSS 0.55%via OSV
CVE-2021-36775High· 8.0
2y ago

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication

Twilightrancher · github.com/rancher/rancherEPSS 0.97%via OSV
CVE-2021-31999High· 8.8
2y ago

Rancher Privilege escalation vulnerability via malicious "Connection" header

Rancher Privilege escalation vulnerability via malicious "Connection" header

Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2021-25318High· 8.8
2y ago

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources

Twilightrancher · github.com/rancher/rancherEPSS 1.1%via OSV
CVE-2023-32192High· 8.3
2y ago

Rancher API Server Cross-site Scripting Vulnerability

Rancher API Server Cross-site Scripting Vulnerability

Twilightrancher · github.com/rancher/apiserverEPSS 0.35%via OSV
CVE-2023-22647Critical· 9.9
3y ago

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Rancher vulnerable to Privilege Escalation via manipulation of Secrets

Midnightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2020-10676High· 8.8
3y ago

Rancher users retain access after moving namespaces into projects they don't have access to

Rancher users retain access after moving namespaces into projects they don't have access to

Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2022-43760High· 8.4
3y ago

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Rancher UI has multiple Cross-Site Scripting (XSS) issues

Twilightrancher · github.com/rancher/rancherEPSS 0.71%via OSV
CVE-2023-22651Critical· 9.9
3y ago

Rancher Webhook is misconfigured during upgrade process

Rancher Webhook is misconfigured during upgrade process

Midnightrancher · github.com/rancher/rancherEPSS 0.78%via OSV
CVE-2021-36782Critical· 9.9PoC
4y ago

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials

Abyssalrancher · github.com/rancher/rancherEPSS 4.2%via OSV
CVE-2019-12274High· 8.8
4y ago

Rancher Privilege Escalation Vulnerability

Rancher Privilege Escalation Vulnerability

Twilightrancher · github.com/rancher/rancherEPSS 1.0%via OSV
CVE-2021-25313Medium· 6.1
4y ago

Rancher Cross-site Scripting Vulnerability

Rancher Cross-site Scripting Vulnerability

Sunlitrancher · github.com/rancher/rancherEPSS 1.5%via OSV
GHSA-wm2r-rp98-8pmhLow
4y ago

Exposure of SSH credentials in Rancher/Fleet

Exposure of SSH credentials in Rancher/Fleet

Sunlitrancher · github.com/rancher/ranchervia OSV
rancher vulnerabilities (CVEs) · VulnSea