Privilege Escalation Vulnerability in Rancher Manager by Rancher
CVE-2026-71404

8.7HIGH

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-71404?

A flaw in Rancher Manager's GlobalRole controller allows unauthorized users to exploit the authz.management.cattle.io/cr-name annotation. By manipulating this annotation, a user with the ability to create or update GlobalRoles can alter an existing ClusterRole's rules—such as cluster-admin—and revoke permissions from any principal associated with it. This alteration persists even after the GlobalRole is removed, leading to potential widespread access issues across the affected system.

Affected Version(s)

Rancher 0 < 2.15.1

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/Pig-Tail
.