« Volver al listado

Rancher

Rancher Manager: vulnerabilidades y CVE

Rancher Manager tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-44939Crítica (9.4)1.3%—19 jun 2026
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an…
CVE-2023-32199Media (4.3)0.22%—29 oct 2025
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only…
CVE-2024-58267Alta (8)0.23%—2 oct 2025
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be…
CVE-2024-58260Alta (7.6)0.46%—2 oct 2025
A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of…
CVE-2025-54468Media (4.7)0.36%—2 oct 2025
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers…
CVE-2024-58259Alta (8.2)0.52%—2 sept 2025
A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution2
  2. T1059 Command and Scripting Interpreter1
  3. T1078 Valid Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1210 Exploitation of Remote Services1
  6. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Rancher