High severity8.7NVD Advisory· Published Sep 3, 2026· Updated Sep 3, 2026
CVE-2026-71404
CVE-2026-71404
Description
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable authz.management.cattle.io/cr-name annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as cluster-admin, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted.
This issue affects Rancher: before 2.15.1.
Affected products
2- Range: <2.15.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.