Vulnerabilities
Vulnerable Software
Suse:  >> Rancher  >> 2.12.2  Security Vulnerabilities
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
CVSS Score
9.5
EPSS Score
0.003
Published
2026-06-30
Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.
CVSS Score
9.4
EPSS Score
0.004
Published
2026-06-29
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
CVSS Score
8.3
EPSS Score
0.002
Published
2026-02-25


Contact Us

Shodan ® - All rights reserved