SUSE rancher是德国SUSE公司开源的一款一套容器管理平台。 SUSE Rancher 2.11.0至2.11.16之前版本、2.12.0至2.12.12之前版本、2.13.0至2.13.8之前版本和2.14.0至2.14.2之前版本存在安全漏洞,该漏洞源于模拟中间件(pkg/auth/requests/impersonate.go)问题,可能导致具有默认用户全局角色的已认证用户获得Rancher控制平面的完全管理访问权限,并传递到其管理的所有下游集群。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59675 | 7.5 HIGH | Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service |
| CVE-2026-25703 | 7.3 HIGH | Potential information leakage from manager /network/graph API in NeuVector |
| CVE-2026-55998 | 5.3 MEDIUM | Cluster Existence Oracle via Unauthenticated Import Endpoint |
| CVE-2026-55996 | 4.3 MEDIUM | Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agent |
No comments yet