← Terug naar overzicht

A critical security flaw was identified in Rancher Manager where the GlobalRole controller derives the target ClusterRole name from a user-settable annotation without verifying ownership. An attacker with delegated GlobalRole create or update permissions can point the annotation at any existing ClusterRole, including cluster-admin, effectively revoking permissions for all principals bound to that role. The vulnerability is particularly dangerous because the damage persists even after the malicious GlobalRole is deleted. This constitutes a privilege escalation and denial-of-access attack vector within Kubernetes RBAC managed by Rancher. All versions of Rancher prior to 2.15.1 are affected. Fixes have been issued via pull requests in the official Rancher GitHub repository. Organizations running Rancher clusters should upgrade immediately to version 2.15.1 or later to remediate the issue.

Affected products

  • Rancher Manager
  • Rancher before 2.15.1

Related CVE's

  • CVE-2026-71404

Categories

  • Cloud & Virtualization
  • Identity & Access