Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71404— Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole

Quick assessment

Affected
SUSE Rancher
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Rancher Manager 中发现了一个漏洞。GlobalRole 控制器从用户可设置的 注解中获取目标 ClusterRole 的名称,并在未验证所有权的情况下直接覆盖该对象的权限规则。拥有被委托的 GlobalRole 创建或更新权限的用户可以将该注解指向任意现有的 ClusterRole(例如 ),从而撤销所有绑定到该角色上的主体的权限。即使删除了恶意创建的 GlobalRole,这一权限变更仍然会保留。 该问题影响 Rancher 版本 2.15.1 之前的所有版本。

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
SUSE Rancher < 2.15.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71404

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it. The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE Rancher 0 ~ 2.15.1 -

II. Public POCs for CVE-2026-71404

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71404

登录查看更多情报信息。

Same Patch Batch · SUSE · 2026-09-03 · 6 CVEs total

CVE-2026-75033 7.7 HIGH Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing
CVE-2026-75035 7.7 HIGH Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scop
CVE-2026-75034 7.4 HIGH Rancher: SAML Assertion Replay
CVE-2026-71403 6.1 MEDIUM Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind
CVE-2026-75036 5.3 MEDIUM Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing

IV. Related Vulnerabilities

V. Comments for CVE-2026-71404

No comments yet


Leave a comment