VYPR

Vendor CVEs

Rancher

All CVEs

56 total · sorted by risk
  • CVE-2026-44935CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.00

    Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

  • CVE-2026-44948MedJun 30, 2026
    risk 0.00cvss epss 0.00

    A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, causing a denial of service.

  • CVE-2026-44949HigJun 30, 2026
    risk 0.00cvss epss 0.00

    A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.8.7, 0.9.0 up to 0.9.6 and 0.10.0 up to 0.10.7. An unauthenticated attacker with network access to the in-cluster rancher-webhook…

  • CVE-2026-44947MedJun 30, 2026
    risk 0.00cvss epss 0.00

    A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from…

  • CVE-2026-44946HigJun 30, 2026
    risk 0.00cvss 7.4epss 0.00

    A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,

  • CVE-2024-21550MedAug 12, 2024
    risk 0.00cvss 6.1epss 0.00

    SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to…

Page 2 of 2