Junglewise Threat Intelligence

CVE-2026-25705: SUSE Rancher path traversal in UI Extensions

CVE-2026-25705 · Severity: high · CVSS 8.4 · Published 2026-05-13

Technologies: github.com/rancher/rancher (Go), Suse Rancher. Vendors: Go, Suse.

Executive brief

Rancher is a popular platform for managing Kubernetes clusters. A vulnerability in its extension system allows a malicious extension to access or overwrite sensitive files on the management server. This could lead to a complete takeover of the Rancher environment, tampering with cluster states, or unauthorized access to the underlying host system.

Technical details

A path traversal vulnerability (CWE-35) exists in Rancher's Extensions mechanism, specifically within the 'compressedEndpoint' field of a 'UIPlugin' deployment and icon references in 'index.yaml'. An attacker with permissions to deploy UI extensions (typically an administrator) can use '../' sequences to escape the intended directory. This allows for overwriting Rancher binaries, modifying configuration files, or accessing the host node filesystem if hostPath volumes are mounted. The vulnerability is exploited by providing a malicious URI or file path that resolves outside the restricted cache or repository directories. Patches have been released to enforce strict path validation and ensure files remain within designated directories.

Affected products

  • SUSE Rancher >= 2.14.0, < 2.14.1; >= 2.13.0, < 2.13.5; >= 2.12.0, < 2.12.9; >= 2.10.11, < 2.11.13

Timeline

  • 2026-04-30: disclosed: Initial disclosure to rancher/rancher repository
  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-13: other: NVD publication date

References

Related threats