Security Advisories and CVEs

Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.

ID Description Date Resolution

CVE-2026-75036

Fixed a vulnerability in Fleet’s Helm template preprocessing where untrusted bundle content could cause the Fleet controller to disclose cluster metadata and information about hosts reachable from the controller.

27 August 2026

Fleet v0.16.1, Fleet v0.15.6, Fleet v0.14.10, Fleet v0.13.15, Fleet v0.12.19

CVE-2026-75035

Fixed a security vulnerability in the Rancher imperative ext Token API (ext.cattle.io/v1 tokens) where any authenticated user can list and watch other users' tokens by supplying a crafted label selector, disclosing token metadata and the stored bearer token hash.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-75034

Fixed a security vulnerability in Rancher’s SAML authentication handler where the assertion replay protection was ineffective in high-availability (multi-replica) deployments, allowing a captured SAML assertion to be replayed against other replicas to create additional authenticated sessions as the victim. All SAML providers were affected.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-75033

Fixed a security vulnerability in Rancher’s project-scoped secretsController where Project Secrets were propagated to namespaces based only on the field.cattle.io/projectId annotation, without validating that the referenced project belonged to the same cluster. A user with namespace-create permissions on one downstream cluster could spoof this annotation to leak Project Secrets from a project in a different cluster they were not authorized to access.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9, Rancher v2.12.13

CVE-2026-71404

Fixed a security vulnerability in Rancher’s GlobalRole controller where a user with delegated create or update permissions for GlobalRole resources could set the authz.management.cattle.io/cr-name annotation to target an arbitrary existing ClusterRole (such as the built-in cluster-admin). The controller then overwrites the rules without an ownership check, stripping permissions from all bound principals and causing a persistent, cluster-wide RBAC lockout on the local management cluster.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-71403

Fixed a security vulnerability in the SUSE Rancher Norman /v3/users API where the update path did not enforce immutability of the username, principalIds, and displayName fields on a User resource. A caller holding update permissions on users could rebind a user’s external principal identity, enabling account takeover during the next external login or creating a denial-of-service condition that left existing role bindings inaccessible.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9