Security Advisories and CVEs
Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.
| ID | Description | Date | Resolution |
|---|---|---|---|
Fixed a vulnerability in Fleet where bundle |
23 September 2026 |
Rancher v2.15.2, v2.14.6, v2.13.10 |
|
Fixed a security vulnerability in Rancher where logging out cleared the browser session cookies but did not delete the corresponding public API session token on the server, so a previously captured session token remained valid until its natural expiry. Only deployments using public API session tokens were affected. |
23 September 2026 |
Rancher v2.15.2 |
|
Fixed a security vulnerability in Rancher where public UI settings exposed on unauthenticated read-only API routes could be modified by a remote unauthenticated user, allowing content to be stored that executes in the browser of users opening the Rancher login page and potentially exposing the local administrator bootstrap password or an active administrator session. The unauthenticated settings routes are now strictly read-only. |
23 September 2026 |
Rancher v2.15.2, v2.14.6, v2.13.10, v2.12.14, v2.11.18 |
|
Fixed a privilege management vulnerability in Fleet where namespace labels and annotations were applied without the bundle service account’s authorization, allowing unauthorized changes to namespace metadata in multi-tenant deployments. |
23 September 2026 |
Rancher v2.15.1, v2.14.6, v2.13.10, v2.12.14 |
|
Fixed a vulnerability in Fleet’s Git webhook receiver that allowed unauthenticated, cross-namespace modification of the |
23 September 2026 |
Rancher v2.15.2 |
|
Fixed a cross-tenant authorization issue in Fleet where labels supplied during agent-initiated cluster registration could cause a cluster to match another tenant’s bundle targets, disclosing that tenant’s manifests and resolved values Secrets. |
23 September 2026 |
Rancher v2.15.1, v2.14.5, v2.13.9, v2.12.13, v2.11.17 |
|
Fixed a path traversal vulnerability in Fleet where untrusted bundle content could reference Helm |
23 September 2026 |
Rancher v2.15.2, v2.14.6, v2.13.10, v2.12.14, v2.11.18 |
|
Fixed a vulnerability in Fleet’s Helm template preprocessing where untrusted bundle content could cause the Fleet controller to disclose cluster metadata and information about hosts reachable from the controller. |
27 August 2026 |
Rancher v2.15.1, v2.14.5, v2.13.9, v2.12.13, v2.11.17 |
|
Fixed a security vulnerability in the Rancher imperative ext Token API ( |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in Rancher’s SAML authentication handler where the assertion replay protection was ineffective in high-availability (multi-replica) deployments, allowing a captured SAML assertion to be replayed against other replicas to create additional authenticated sessions as the victim. All SAML providers were affected. |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in Rancher’s project-scoped |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9, Rancher v2.12.13 |
|
Fixed a security vulnerability in Rancher’s GlobalRole controller where a user with delegated |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |
|
Fixed a security vulnerability in the SUSE Rancher Norman |
27 August 2026 |
Rancher v2.15.1, Rancher v2.14.5, Rancher v2.13.9 |