Back

CRITICAL

Rancher: Restricted Administrator can change Administrator's passwords

Published Apr 11, 2025

Description

A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Apr 11, 2025
Updated Feb 26, 2026
Reserved Jan 15, 2025
CISA Vulnrichment
Updated Apr 12, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-8P83-CPFG-FJ3G