Rancher

Vendor:

First CVE: Mar 29, 2017 · Active for 9 years

65
Total CVEs
More Total CVEs than 99% of tracked products
8.1
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rancher over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2017
9 years ago
Most Recent CVE
Jul 7, 2026
20 days ago

CVE Severity & Scoring

Rancher65 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (1.5%)
Network63 (96.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low57 (87.7%)
High8 (12.3%)
Unknown0 (0.0%)
User Interaction
None52 (80.0%)
Unknown0 (0.0%)
Required12 (18.5%)
Privileges Required
Low33 (50.8%)
High17 (26.2%)
None15 (23.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (65 CVEs).

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be us
Jul 2, 20269.943NONO
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to us
Sep 7, 20229.943NOYES
Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13
Jun 30, 20268.839NONO
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.
Jun 29, 20268.839NONO
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets fro
May 13, 20269.939NONO
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.option
Jul 7, 20268.838NONO
Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5
Jul 6, 20268.236NONO
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow
Jun 19, 20269.435NONO
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in th
Jun 30, 20267.434NONO
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles,
Jul 6, 20267.032NONO

Exploit Exposure

Signals from CVEs in this product scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (65 CVEs).

Media Mentions

Signals from CVEs in this product scope (65 CVEs).

Top CNAs Publishing CVEs For Rancher

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.414.72.3%00