Security Advisories and CVEs
Rancher is committed to informing the community of security issues in our products. Rancher will publish security advisories and CVEs (Common Vulnerabilities and Exposures) for issues we have resolved. New security advisories are also published in Rancher’s GitHub security page.
| ID | Description | Date | Resolution |
|---|---|---|---|
Fixed a vulnerability in Fleet’s Helm template preprocessing where untrusted bundle content could cause the Fleet controller to disclose cluster metadata and information about hosts reachable from the controller. |
26 August 2026 |
Fleet v0.16.1, Fleet v0.15.6, Fleet v0.14.10, Fleet v0.13.15, Fleet v0.12.19 |
|
Fixed a security vulnerability in Rancher’s unauthenticated cluster import endpoint where an attacker could enumerate valid cluster IDs and detect private registry usage by observing distinguishable HTTP response codes. |
30 July 2026 |
Rancher v2.14.4, Rancher v2.13.8, Rancher v2.12.12, and Rancher v2.11.16. |
|
Fixed a security vulnerability where an unauthenticated attacker with cluster-internal network access could flood TLS listeners in |
30 July 2026 |
Rancher v2.14.4, Rancher v2.13.8, Rancher v2.12.12, and Rancher v2.11.16. |
|
Fixed a critical security vulnerability in Rancher’s impersonation middleware ( |
30 July 2026 |
Rancher v2.14.4, Rancher v2.13.8, Rancher v2.12.12, and Rancher v2.11.16. |
|
Fixed a security vulnerability in rancher-webhook where the FleetWorkspace mutating admission webhook performed side effects without authenticating requests, allowing a pod inside the cluster to create arbitrary namespaces and inject RBAC bindings. |
29 June 2026 |
Rancher v2.14.3, Rancher v2.13.7, Rancher v2.12.11 and Rancher v2.11.15 |
|
Fixed a security vulnerability in Rancher’s SAML authentication handler where a valid signed SAML response could be replayed by an attacker who had also captured the victim’s pre-authentication SAML state cookie, allowing the attacker to create a separate authenticated session with the victim’s permissions. All SAML providers (Okta, Ping, ADFS, Keycloak, Shibboleth) were affected. |
29 June 2026 |
Rancher v2.14.3, Rancher v2.13.7, Rancher v2.12.11 and Rancher v2.11.15 |
|
Rancher now validates the |
27 May 2026 |
Rancher v2.14.2, Rancher v2.13.6, v2.12.10, v2.11.14, and v2.10.12 |
|
Rancher now protects against arbitrary file access via path traversal in Rancher Extensions. Note by default only users with administrative permissions can deploy UI extensions unless explicit permission is granted to other users. |
30 Apr 2026 |
||
Rancher now provides new versions of the Rancher Backup chart which prevent the leak of secret S3 credentials via the Rancher Backup pod log. |
29 Jan 2026 |
||
Rancher now removes the ability to fetch CA certificates stored in Rancher’s setting |
29 Jan 2026 |
||
Rancher now removes the corresponding ClusterRoleBindings whenever the admin GlobalRole or its GlobalRoleBindings are deleted. Previously orphaned ClusterRoleBindings were marked with the annotation |
23 Oct 2025 |
||
Setting the username of one user as the same username of another user causes an error when either user attempts to log in. Therefore, a user with the |
25 Sep 2025 |
||
The Rancher CLI is modified to print the |
25 Sep 2025 |
||
|
25 Sep 2025 |
||
POSTs to the Rancher API endpoints are now limited to 1 Mi; this is configurable through the settings if you need a larger limit. The Rancher authentication endpoints are configured independently of the main public API (as you might need bigger payloads in the other API endpoints). Suppose you need to increase the maximum allowed payload for authentication. In that case, you can set the environment variable |
28 Aug 2025 |
||
Following a recent change excluding Helm values files from bundles, an edge case subsisted where the values files referenced in |
28 Aug 2025 |
||
This vulnerability only affects customers using Continuous Delivery with Fleet where Fleet does not validate a server’s certificate when connecting through SSH. This can allow for a main-in-the-middle-attack against Fleet. The fix provides a new
If
If
This happens regardless of whether a A limitation with the default
|
24 Apr 2025 |
||
A vulnerability was found where users could create a project and then gain access to arbitrary projects. As a fix, a new field has been added to projects called the The field is populated automatically during project creation and is formatted as |
24 Apr 2025 |
||
A vulnerability was found where users with permission to create a service in the Kubernetes cluster where Rancher is deployed can take over the Rancher UI, display their own UI, and gather sensitive information. This is only possible when the setting |
24 Apr 2025 |
||
A vulnerability has been identified within Rancher where a Restricted Administrator can change the password of Administrators and take over their accounts. A Restricted Administrator should not be allowed to change the password of more privileged users unless it contains the Manage Users permissions. A new validation has been added to block a user from editing or deleting another user with more permissions than themselves. Rancher deployments where the Restricted Administrator role is not being used are not affected by this CVE. |
31 Mar 2025 |