Security Advisories and CVEs
Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.
| ID | Description | Date | Resolution |
|---|---|---|---|
Fixed a vulnerability in Fleet’s Helm template preprocessing where untrusted bundle content could cause the Fleet controller to disclose cluster metadata and information about hosts reachable from the controller. |
27 August 2026 |
Fleet v0.16.1, Fleet v0.15.6, Fleet v0.14.10, Fleet v0.13.15, Fleet v0.12.19 |
|
Fixed a security vulnerability in the Rancher imperative ext Token API ( |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in Rancher’s SAML authentication handler where the assertion replay protection was ineffective in high-availability (multi-replica) deployments, allowing a captured SAML assertion to be replayed against other replicas to create additional authenticated sessions as the victim. All SAML providers were affected. |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in Rancher’s project-scoped |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9, Rancher v2.12.13 |
|
Fixed a security vulnerability in Rancher’s GlobalRole controller where a user with delegated |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in the SUSE Rancher Norman |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |