Rancher operates a container management and orchestration platform that, despite a narrow product portfolio, occupies a critical position in Kubernetes deployment and lifecycle management across enterprises. Its vulnerability footprint centers on access-control and permission-assignment issues, alongside authorization and authentication weaknesses, which reflect the platform's role in managing sensitive cluster operations and multi-tenant resource isolation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rancher over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25320CRITICAL A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in thi | Jul 15, 2021 | 9.9 | 30 | NO | NO |
CVE-2021-36776HIGH A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10. | Apr 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-36775HIGH a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2. | Apr 4, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-31999HIGH A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the cluster by forging the "Impersonate-User" o | Jul 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-25318HIGH A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: | Jul 15, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rancher.
Media articles that mention a CVE ID that affects a product developed by Rancher — matched by CVE ID, not by vendor name.