Self-Signed CA Certificate Vulnerability in Rancher Manager by Rancher
CVE-2025-67601

8.3HIGH

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2025-67601?

A vulnerability has been discovered in Rancher Manager that arises when users utilize self-signed CA certificates without properly configuring the Rancher CLI. Specifically, passing the -skip-verify flag during login without the -cacert flag leads to the CLI making attempts to retrieve CA certificates from the settings, potentially exposing the system to security risks. It is crucial for users to ensure that the appropriate flags are implemented to safeguard against unauthorized access and other associated threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

rancher 0 < 0.0.0-20260129092249-bb0625fd1896

rancher 2.13.0 < 2.13.2

rancher 2.12.0 < 2.12.6

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.