High severity8.4GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-25705
CVE-2026-25705
Description
A vulnerability has been identified in Rancher's Extensions where malicious code can be injected in Rancher through a path traversal in the compressedEndpoint field inside a UIPlugin deployment. A malicious UI extension could abuse that to: * Overwrite Rancher binaries or configuration to inject code.
- Write to /var/lib/rancher/ to tamper with cluster state.
- If hostPath volumes are mounted, write to the host node filesystem.
- Use this issue to chain with other attack vectors.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.