Rancher
- Products in analyzed data
- 3
- Catalog vulnerabilities
- 7
Severity across 5 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 5 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, Rancher recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Rancher had the most security vulnerabilities in the Rancher ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-55997Long-lived Rancher registration token exposed in plaintext | Exploitation statusNot known exploited | FixYes | Affected productRancher | Published08/05/2026 | SeverityHigh |
CVE-2026-44543Local Path Provisioner: HelperPod Template Injection | Exploitation statusNot known exploited | FixYes | Affected productlocal-path-provisioner | Published05/28/2026 | SeverityHigh |
CVE-2021-36776Steve API proxy impersonation | Exploitation statusNot confirmed | FixYes | Affected productRancher | Published04/01/2022 | SeverityHigh |
CVE-2021-36775Deleting PRTBs associated to a group doesn't cause deletion of corresponding RoleBindings | Exploitation statusNot confirmed | FixYes | Affected productRancher | Published04/01/2022 | SeverityHigh |
CVE-2021-31999Rancher: Privilege escalation vulnerability via malicious Connection header | Exploitation statusNot confirmed | FixYes | Affected productRancher | Published07/15/2021 | SeverityHigh |
CVE-2021-25320Rancher: Cloud credentials can be used through proxy API by users without access | Exploitation statusNot confirmed | FixYes | Affected productRancher | Published07/15/2021 | SeverityCritical |
CVE-2021-25318rancher: API group not properly specified when creating Kubernetes RBAC resources | Exploitation statusNot confirmed | FixYes | Affected productRancher | Published07/15/2021 | SeverityHigh |