Known Vulnerabilities for Rancher by Suse
Listed below are 10 of the newest known vulnerabilities associated with "Rancher" by "Suse".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59675 json | When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size lim... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-55997 json | Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens wer... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-55996 json | A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent componen... | Not Provided | 2026-08-05 | 2026-08-05 |
| CVE-2026-44949 json | A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up t... | Not Provided | 2026-06-30 | 2026-06-30 |
| CVE-2026-44948 json | A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0... | Not Provided | 2026-06-30 | 2026-06-30 |
| CVE-2026-44947 json | A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and... | Not Provided | 2026-06-30 | 2026-06-30 |
| CVE-2026-44946 json | A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time u... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-44945 json | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An auth... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-44939 json | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId... | Not Provided | 2026-06-19 | 2026-06-24 |
| CVE-2026-44937 json | Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 bef... | Not Provided | 2026-07-06 | 2026-07-06 |