High severity8.8NVD Advisory· Published Apr 4, 2022· Updated Jun 17, 2026
CVE-2021-36776
CVE-2021-36776
Description
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rancher/rancherGo | >= 2.5.0, < 2.5.10 | 2.5.10 |
Affected products
6- osv-coords5 versionspkg:apk/chainguard/harvesterpkg:apk/chainguard/harvester-fipspkg:apk/chainguard/harvester-fips-webhookpkg:apk/chainguard/harvester-webhookpkg:golang/github.com/rancher/rancher
< 1.8.1-r1+ 4 more
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: < 1.8.1-r0
- (no CPE)range: < 1.8.1-r0
- (no CPE)range: < 1.8.1-r1
- (no CPE)range: >= 2.5.0, < 2.5.10
Patches
Vulnerability mechanics
References
3- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-gvh9-xgrq-r8hwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-36776ghsaADVISORY
News mentions
0No linked articles in our index yet.