SUSE Rancher

12 known vulnerabilities in SUSE Rancher, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-88808 CVSS 8.8 high A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own…
  • CVE-2026-88805 CVSS 8.1 high Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged…
  • CVE-2026-88804 CVSS 9.6 critical An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the…
  • CVE-2026-93540 CVSS 6.5 medium A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and…
  • CVE-2026-93539 CVSS 5.4 medium A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured…
  • CVE-2026-93538 CVSS 7.1 high A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels…
  • CVE-2026-93537 CVSS 6.5 medium A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through…
  • CVE-2026-75035 CVSS 7.1 high A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the…
  • CVE-2026-75034 CVSS 7.4 high A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed…
  • CVE-2026-75033 CVSS 7.7 high A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId`…
  • CVE-2026-71404 CVSS 8.7 high A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable…
  • CVE-2026-71403 CVSS 6.1 medium A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and…