VYPR

Rancher

by Rancher

Source repositories

CVEs (45)

  • CVE-2025-23387MedApr 11, 2025
    risk 0.27cvss 5.3epss 0.01

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from…

  • CVE-2024-58269MedOct 29, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entity with access to Rancher audit logs.

  • CVE-2023-32199MedOct 29, 2025
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule…

  • CVE-2026-44947MedJun 30, 2026
    risk 0.00cvss —epss 0.00

    A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from…

  • CVE-2026-44946HigJun 30, 2026
    risk 0.00cvss 7.4epss 0.00

    A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,

Page 3 of 3