Privilege Escalation Vulnerability in Rancher Manager by Rancher
CVE-2026-71404
8.7HIGH
What is CVE-2026-71404?
A flaw in Rancher Manager's GlobalRole controller allows unauthorized users to exploit the authz.management.cattle.io/cr-name annotation. By manipulating this annotation, a user with the ability to create or update GlobalRoles can alter an existing ClusterRole's rules—such as cluster-admin—and revoke permissions from any principal associated with it. This alteration persists even after the GlobalRole is removed, leading to potential widespread access issues across the affected system.
Affected Version(s)
Rancher 0 < 2.15.1