{"schema_version":1,"title":"github.com/rancher/rancher (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 41 vulnerabilities in github.com/rancher/rancher (Go): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-41053, was published on 30 June 2026.","url":"https://junglewise.ai/threats/technologies/github-com-rancher-rancher","json_url":"https://junglewise.ai/threats/technologies/github-com-rancher-rancher.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-rancher-rancher","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":41,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":13},"latest":[{"cve":"CVE-2026-41053","cvss":8.8,"epss":0.0052,"slug":"cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication","title":"SUSE Rancher privilege escalation in GitHub App authentication provider","severity":"high","exploited":false,"published_at":"2026-06-30T12:16:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication"},{"cve":"CVE-2026-41052","cvss":8.4,"epss":0.0042,"slug":"cve-2026-41052-suse-rancher-privilege-escalation-in-project-owner-role","title":"SUSE Rancher privilege escalation in Project Owner role","severity":"high","exploited":false,"published_at":"2026-06-29T16:16:39.87+00:00","url":"https://junglewise.ai/threats/cve-2026-41052-suse-rancher-privilege-escalation-in-project-owner-role"},{"cve":"CVE-2026-44939","cvss":9.6,"epss":0.0131,"slug":"cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint","title":"SUSE Rancher command injection in cluster import endpoint","severity":"critical","exploited":false,"published_at":"2026-06-19T13:16:30.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint"},{"cve":"CVE-2026-25705","cvss":8.4,"epss":0.0049,"slug":"cve-2026-25705-suse-rancher-path-traversal-in-ui-extensions","title":"SUSE Rancher path traversal in UI Extensions","severity":"high","exploited":false,"published_at":"2026-05-13T08:16:16.083+00:00","url":"https://junglewise.ai/threats/cve-2026-25705-suse-rancher-path-traversal-in-ui-extensions"},{"cve":"CVE-2021-25320","cvss":3.1,"epss":0.0086,"slug":"cve-2021-25320-rancher-cloud-credentials-can-be-used-through-proxy-api-by-users","title":"GO-2026-4589 - Rancher cloud credentials can be used through proxy API by users without access in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2026-03-10T18:28:01+00:00","url":"https://junglewise.ai/threats/cve-2021-25320-rancher-cloud-credentials-can-be-used-through-proxy-api-by-users"},{"slug":"go-2026-4590-rancher-s-restricted-podsecuritypolicy-does-not-prevent-dea62d9a","title":"GO-2026-4590 - Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user in github.com/rancher/rancher","severity":"info","exploited":false,"published_at":"2026-03-10T18:28:01+00:00","url":"https://junglewise.ai/threats/go-2026-4590-rancher-s-restricted-podsecuritypolicy-does-not-prevent-dea62d9a"},{"cvss":4,"slug":"rancher-s-restricted-podsecuritypolicy-does-not-prevent-containers-from-eb706e8d","title":"Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user","severity":"medium","exploited":false,"published_at":"2026-03-03T14:51:36+00:00","url":"https://junglewise.ai/threats/rancher-s-restricted-podsecuritypolicy-does-not-prevent-containers-from-eb706e8d"},{"cve":"CVE-2025-67601","cvss":3.1,"epss":0.0016,"slug":"cve-2025-67601-rancher-cli-skips-tls-verification-on-rancher-cli-login-command","title":"GO-2026-4393 - Rancher CLI skips TLS verification on Rancher CLI login command in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2026-02-02T21:05:59+00:00","url":"https://junglewise.ai/threats/cve-2025-67601-rancher-cli-skips-tls-verification-on-rancher-cli-login-command"},{"cve":"CVE-2024-58269","cvss":3.1,"epss":0.0027,"slug":"cve-2024-58269-rancher-exposes-sensitive-information-through-audit-logs","title":"GO-2025-4074 - Rancher exposes sensitive information through audit logs in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-10-30T15:02:33+00:00","url":"https://junglewise.ai/threats/cve-2024-58269-rancher-exposes-sensitive-information-through-audit-logs"},{"cve":"CVE-2023-32199","cvss":3.1,"epss":0.0021,"slug":"cve-2023-32199-rancher-user-retains-access-to-clusters-despite-global-role","title":"GO-2025-4073 - Rancher user retains access to clusters despite Global Role removal in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-10-30T15:02:33+00:00","url":"https://junglewise.ai/threats/cve-2023-32199-rancher-user-retains-access-to-clusters-despite-global-role"},{"cve":"CVE-2024-58260","cvss":3.1,"epss":0.0046,"slug":"cve-2024-58260-rancher-update-on-users-can-deny-the-service-to-the-admin","title":"GO-2025-3983 - Rancher update on users can deny the service to the admin in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-10-23T16:25:09+00:00","url":"https://junglewise.ai/threats/cve-2024-58260-rancher-update-on-users-can-deny-the-service-to-the-admin"},{"cve":"CVE-2024-58267","cvss":3.1,"epss":0.0023,"slug":"cve-2024-58267-rancher-cli-saml-authentication-is-vulnerable-to-phishing-attacks","title":"GO-2025-3984 - Rancher CLI SAML authentication is vulnerable to phishing attacks in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-10-23T16:25:09+00:00","url":"https://junglewise.ai/threats/cve-2024-58267-rancher-cli-saml-authentication-is-vulnerable-to-phishing-attacks"},{"cve":"CVE-2025-54468","cvss":3.1,"epss":0.0036,"slug":"cve-2025-54468-rancher-sends-sensitive-information-to-external-services-through","title":"GO-2025-3982 - Rancher sends sensitive information to external services through the `/meta/proxy` endpoint in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-10-23T16:25:09+00:00","url":"https://junglewise.ai/threats/cve-2025-54468-rancher-sends-sensitive-information-to-external-services-through"},{"cve":"CVE-2024-58259","cvss":3.1,"epss":0.0052,"slug":"cve-2024-58259-rancher-affected-by-unauthenticated-denial-of-service","title":"GO-2025-3923 - Rancher affected by unauthenticated Denial of Service in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-09-08T14:13:10+00:00","url":"https://junglewise.ai/threats/cve-2024-58259-rancher-affected-by-unauthenticated-denial-of-service"},{"cve":"CVE-2024-22031","cvss":3.1,"slug":"cve-2024-22031-rancher-users-who-can-create-projects-can-gain-access-to","title":"GO-2025-3647 - Rancher users who can create Projects can gain access to arbitrary projects in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-05-05T16:13:00+00:00","url":"https://junglewise.ai/threats/cve-2024-22031-rancher-users-who-can-create-projects-can-gain-access-to"},{"cve":"CVE-2025-23391","cvss":3.1,"epss":0.0046,"slug":"cve-2025-23391-rancher-restricted-administrator-can-change-administrator-s","title":"GO-2025-3586 - Rancher: Restricted Administrator can change Administrator's passwords in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-04-02T16:02:03+00:00","url":"https://junglewise.ai/threats/cve-2025-23391-rancher-restricted-administrator-can-change-administrator-s"},{"cve":"CVE-2025-23388","cvss":3.1,"epss":0.0059,"slug":"cve-2025-23388-rancher-allows-an-unauthenticated-stack-overflow-in-v3-public","title":"GO-2025-3491 - Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-23388-rancher-allows-an-unauthenticated-stack-overflow-in-v3-public"},{"cve":"CVE-2025-23387","cvss":3.1,"epss":0.0058,"slug":"cve-2025-23387-rancher-s-saml-based-login-via-cli-can-be-denied-by","title":"GO-2025-3489 - Rancher's SAML-based login via CLI can be denied by unauthenticated users in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-23387-rancher-s-saml-based-login-via-cli-can-be-denied-by"},{"cve":"CVE-2025-23389","cvss":3.1,"epss":0.0047,"slug":"cve-2025-23389-rancher-does-not-properly-validate-account-bindings-in-saml","title":"GO-2025-3490 - Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login in github.com/rancher/r","severity":"low","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-23389-rancher-does-not-properly-validate-account-bindings-in-saml"},{"cve":"CVE-2024-52281","cvss":3.1,"epss":0.0055,"slug":"cve-2024-52281-rancher-ui-has-stored-cross-site-scripting-vulnerability","title":"GO-2025-3391 - Rancher UI has Stored Cross-site Scripting vulnerability in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2025-01-15T15:20:27+00:00","url":"https://junglewise.ai/threats/cve-2024-52281-rancher-ui-has-stored-cross-site-scripting-vulnerability"},{"cve":"CVE-2024-52282","cvss":3.1,"epss":0.0045,"slug":"cve-2024-52282-rancher-helm-applications-may-have-sensitive-values-leaked","title":"GO-2024-3280 - Rancher Helm Applications may have sensitive values leaked in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-11-21T19:52:49+00:00","url":"https://junglewise.ai/threats/cve-2024-52282-rancher-helm-applications-may-have-sensitive-values-leaked"},{"cve":"CVE-2024-22036","cvss":3.1,"epss":0.0079,"slug":"cve-2024-22036-rancher-remote-code-execution-via-cluster-node-drivers","title":"GO-2024-3221 - Rancher Remote Code Execution via Cluster/Node Drivers in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-10-28T15:20:02+00:00","url":"https://junglewise.ai/threats/cve-2024-22036-rancher-remote-code-execution-via-cluster-node-drivers"},{"cve":"CVE-2022-45157","cvss":3.1,"epss":0.0044,"slug":"cve-2022-45157-exposure-of-vsphere-s-cpi-and-csi-credentials-in-rancher","title":"GO-2024-3223 - Exposure of vSphere's CPI and CSI credentials in Rancher in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-10-28T15:20:02+00:00","url":"https://junglewise.ai/threats/cve-2022-45157-exposure-of-vsphere-s-cpi-and-csi-credentials-in-rancher"},{"cve":"CVE-2023-32196","cvss":3.1,"epss":0.0055,"slug":"cve-2023-32196-rancher-s-external-roletemplates-can-lead-to-privilege-escalation","title":"GO-2024-3220 - Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-10-28T15:20:02+00:00","url":"https://junglewise.ai/threats/cve-2023-32196-rancher-s-external-roletemplates-can-lead-to-privilege-escalation"},{"cve":"CVE-2024-22030","cvss":3.1,"epss":0.0042,"slug":"cve-2024-22030-rancher-agents-can-be-hijacked-by-taking-over-the-rancher-server","title":"GO-2024-3161 - Rancher agents can be hijacked by taking over the Rancher Server URL in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-10-09T20:29:23+00:00","url":"https://junglewise.ai/threats/cve-2024-22030-rancher-agents-can-be-hijacked-by-taking-over-the-rancher-server"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vulnerabilities":188,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"}],"technology":{"hub":true,"name":"github.com/rancher/rancher (Go)","slug":"github-com-rancher-rancher","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://rancher.com/","repo_url":"https://github.com/rancher/rancher","description":"Rancher is an open-source multi-cluster orchestration platform for managing Kubernetes clusters.","url":"https://junglewise.ai/threats/technologies/github-com-rancher-rancher"},"most_severe":[{"cve":"CVE-2026-44939","cvss":9.6,"epss":0.0131,"slug":"cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint","title":"SUSE Rancher command injection in cluster import endpoint","severity":"critical","exploited":false,"published_at":"2026-06-19T13:16:30.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44939-suse-rancher-command-injection-in-cluster-import-endpoint"},{"cve":"CVE-2026-41053","cvss":8.8,"epss":0.0052,"slug":"cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication","title":"SUSE Rancher privilege escalation in GitHub App authentication provider","severity":"high","exploited":false,"published_at":"2026-06-30T12:16:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-41053-suse-rancher-privilege-escalation-in-github-app-authentication"},{"cve":"CVE-2026-25705","cvss":8.4,"epss":0.0049,"slug":"cve-2026-25705-suse-rancher-path-traversal-in-ui-extensions","title":"SUSE Rancher path traversal in UI Extensions","severity":"high","exploited":false,"published_at":"2026-05-13T08:16:16.083+00:00","url":"https://junglewise.ai/threats/cve-2026-25705-suse-rancher-path-traversal-in-ui-extensions"},{"cve":"CVE-2026-41052","cvss":8.4,"epss":0.0042,"slug":"cve-2026-41052-suse-rancher-privilege-escalation-in-project-owner-role","title":"SUSE Rancher privilege escalation in Project Owner role","severity":"high","exploited":false,"published_at":"2026-06-29T16:16:39.87+00:00","url":"https://junglewise.ai/threats/cve-2026-41052-suse-rancher-privilege-escalation-in-project-owner-role"},{"cvss":4,"slug":"rancher-s-restricted-podsecuritypolicy-does-not-prevent-containers-from-eb706e8d","title":"Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user","severity":"medium","exploited":false,"published_at":"2026-03-03T14:51:36+00:00","url":"https://junglewise.ai/threats/rancher-s-restricted-podsecuritypolicy-does-not-prevent-containers-from-eb706e8d"},{"cve":"CVE-2023-22649","cvss":3.1,"epss":0.0204,"slug":"cve-2023-22649-rancher-audit-log-leaks-sensitive-information","title":"GO-2024-2537 - Rancher 'Audit Log' leaks sensitive information in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2023-22649-rancher-audit-log-leaks-sensitive-information"},{"cve":"CVE-2018-20321","cvss":3.1,"epss":0.0177,"slug":"cve-2018-20321-access-control-bypass","title":"GO-2022-0644 - Access Control Bypass in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2018-20321-access-control-bypass"},{"cve":"CVE-2017-7297","cvss":3.1,"epss":0.0149,"slug":"cve-2017-7297-rancher-access-control-vulnerability","title":"GO-2023-1973 - Rancher Access Control Vulnerability in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-08-20T20:32:20+00:00","url":"https://junglewise.ai/threats/cve-2017-7297-rancher-access-control-vulnerability"},{"cve":"CVE-2021-36776","cvss":3.1,"epss":0.0112,"slug":"cve-2021-36776-rancher-s-steve-api-component-improper-authorization-check-allows","title":"GO-2024-2771 - Rancher's Steve API Component Improper authorization check allows privilege escalation in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2024-06-05T15:10:52+00:00","url":"https://junglewise.ai/threats/cve-2021-36776-rancher-s-steve-api-component-improper-authorization-check-allows"},{"cve":"CVE-2019-13209","cvss":3.1,"epss":0.011,"slug":"cve-2019-13209-rancher-vulnerable-to-cross-site-request-forgery-csrf","title":"GO-2022-0755 - Cross-site request forgery in github.com/rancher/rancher","severity":"low","exploited":false,"published_at":"2021-05-18T15:42:40+00:00","url":"https://junglewise.ai/threats/cve-2019-13209-rancher-vulnerable-to-cross-site-request-forgery-csrf"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}