rancher has 28 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 7 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 7. The median CVSS is 8.8 (high), with 10 rated critical. None have a confirmed exploitation report. Most affected products: github.com/rancher/rancher (23), github.com/rancher/fleet (4), github.com/rancher/apiserver (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 7 prev 1
Products
- github.com/rancher/rancher 23
- github.com/rancher/fleet 4
- github.com/rancher/apiserver 1
Worst active — by depth score
CVE-2021-36782Critical· 9.9Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials67CVE-2026-44935Critical· 9.9Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer55CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers55CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access55CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets55
rancher vulnerabilities
CVEs affecting rancher, newest first. Open any entry for full detail, references, and exploit status.
28 CVEsRSS
CVE-2026-44938High· 8.8Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-44937High· 7.5Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
CVE-2026-44939Critical· 9.6Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-44936Medium· 5.0Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
CVE-2026-44935Critical· 9.9Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVE-2026-41053High· 8.8Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
CVE-2026-41052Critical· 8.4Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
Rancher Extensions have arbitrary file access via path traversal
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access
Rancher cloud credentials can be used through proxy API by users without access
CVE-2022-21951Medium· 6.8Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
CVE-2023-22648High· 8.0Rancher's Azure AD permission changes are not reflected on active sessions
Rancher's Azure AD permission changes are not reflected on active sessions
CVE-2021-36783Critical· 9.9Rancher doesn't properly sanitize credentials in cluster template answers
Rancher doesn't properly sanitize credentials in cluster template answers
CVE-2022-31247Critical· 9.1Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
Rancher UI has Stored Cross-site Scripting vulnerability
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2021-36775High· 8.0Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
Rancher's Failure to delete orphaned role bindings does not revoke project level access from group based authentication
CVE-2021-31999High· 8.8Rancher Privilege escalation vulnerability via malicious "Connection" header
Rancher Privilege escalation vulnerability via malicious "Connection" header
CVE-2021-25318High· 8.8Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
Rancher does not properly specify ApiGroup when creating Kubernetes RBAC resources
CVE-2023-32192High· 8.3Rancher API Server Cross-site Scripting Vulnerability
Rancher API Server Cross-site Scripting Vulnerability
CVE-2023-22647Critical· 9.9Rancher vulnerable to Privilege Escalation via manipulation of Secrets
Rancher vulnerable to Privilege Escalation via manipulation of Secrets
CVE-2020-10676High· 8.8Rancher users retain access after moving namespaces into projects they don't have access to
Rancher users retain access after moving namespaces into projects they don't have access to
CVE-2022-43760High· 8.4Rancher UI has multiple Cross-Site Scripting (XSS) issues
Rancher UI has multiple Cross-Site Scripting (XSS) issues
CVE-2023-22651Critical· 9.9Rancher Webhook is misconfigured during upgrade process
Rancher Webhook is misconfigured during upgrade process
CVE-2021-36782Critical· 9.9PoCRancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
CVE-2019-12274High· 8.8Rancher Privilege Escalation Vulnerability
Rancher Privilege Escalation Vulnerability
CVE-2021-25313Medium· 6.1Rancher Cross-site Scripting Vulnerability
Rancher Cross-site Scripting Vulnerability
GHSA-wm2r-rp98-8pmhLowExposure of SSH credentials in Rancher/Fleet
Exposure of SSH credentials in Rancher/Fleet