Security Advisories and CVEs

Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.

ID Description Date Resolution

CVE-2026-88808

Fixed a vulnerability in Fleet where bundle downstreamResources were copied to downstream clusters with the agent’s privileged credentials, allowing a tenant to write Secrets and ConfigMaps, and create namespaces, outside of their authorization scope.

23 September 2026

Rancher v2.15.2, v2.14.6, v2.13.10

CVE-2026-88805

Fixed a security vulnerability in Rancher where logging out cleared the browser session cookies but did not delete the corresponding public API session token on the server, so a previously captured session token remained valid until its natural expiry. Only deployments using public API session tokens were affected.

23 September 2026

Rancher v2.15.2

CVE-2026-88804

Fixed a security vulnerability in Rancher where public UI settings exposed on unauthenticated read-only API routes could be modified by a remote unauthenticated user, allowing content to be stored that executes in the browser of users opening the Rancher login page and potentially exposing the local administrator bootstrap password or an active administrator session. The unauthenticated settings routes are now strictly read-only.

23 September 2026

Rancher v2.15.2, v2.14.6, v2.13.10, v2.12.14, v2.11.18

CVE-2026-93540

Fixed a privilege management vulnerability in Fleet where namespace labels and annotations were applied without the bundle service account’s authorization, allowing unauthorized changes to namespace metadata in multi-tenant deployments.

23 September 2026

Rancher v2.15.1, v2.14.6, v2.13.10, v2.12.14

CVE-2026-93539

Fixed a vulnerability in Fleet’s Git webhook receiver that allowed unauthenticated, cross-namespace modification of the GitRepo polling interval when no webhook secret was configured.

23 September 2026

Rancher v2.15.2

CVE-2026-93538

Fixed a cross-tenant authorization issue in Fleet where labels supplied during agent-initiated cluster registration could cause a cluster to match another tenant’s bundle targets, disclosing that tenant’s manifests and resolved values Secrets.

23 September 2026

Rancher v2.15.1, v2.14.5, v2.13.9, v2.12.13, v2.11.17

CVE-2026-93537

Fixed a path traversal vulnerability in Fleet where untrusted bundle content could reference Helm valuesFiles entries outside the bundle directory, disclosing their contents through the generated Bundle.

23 September 2026

Rancher v2.15.2, v2.14.6, v2.13.10, v2.12.14, v2.11.18

CVE-2026-75036

Fixed a vulnerability in Fleet’s Helm template preprocessing where untrusted bundle content could cause the Fleet controller to disclose cluster metadata and information about hosts reachable from the controller.

27 August 2026

Rancher v2.15.1, v2.14.5, v2.13.9, v2.12.13, v2.11.17

CVE-2026-75035

Fixed a security vulnerability in the Rancher imperative ext Token API (ext.cattle.io/v1 tokens) where any authenticated user can list and watch other users' tokens by supplying a crafted label selector, disclosing token metadata and the stored bearer token hash.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-75034

Fixed a security vulnerability in Rancher’s SAML authentication handler where the assertion replay protection was ineffective in high-availability (multi-replica) deployments, allowing a captured SAML assertion to be replayed against other replicas to create additional authenticated sessions as the victim. All SAML providers were affected.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-75033

Fixed a security vulnerability in Rancher’s project-scoped secretsController where Project Secrets were propagated to namespaces based only on the field.cattle.io/projectId annotation, without validating that the referenced project belonged to the same cluster. A user with namespace-create permissions on one downstream cluster could spoof this annotation to leak Project Secrets from a project in a different cluster they were not authorized to access.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9, Rancher v2.12.13

CVE-2026-71404

Fixed a security vulnerability in Rancher’s GlobalRole controller where a user with delegated create or update permissions for GlobalRole resources could set the authz.management.cattle.io/cr-name annotation to target an arbitrary existing ClusterRole (such as the built-in cluster-admin). The controller then overwrites the rules without an ownership check, stripping permissions from all bound principals and causing a persistent, cluster-wide RBAC lockout on the local management cluster.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9

CVE-2026-71403

Fixed a security vulnerability in the SUSE Rancher Norman /v3/users API where the update path did not enforce immutability of the username, principalIds, and displayName fields on a User resource. A caller holding update permissions on users could rebind a user’s external principal identity, enabling account takeover during the next external login or creating a denial-of-service condition that left existing role bindings inaccessible.

27 August 2026

Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9