logo

Silent Leak: High-Severity Rancher CLI Flaw Exposes Admin Credentials

ID: 009194b9-a9d2-53cc-9a1b-af33d5d103cc

STIX ID: report--009194b9-a9d2-53cc-9a1b-af33d5d103cc

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2025-67601, CVSS 8.4) in the Rancher CLI causes TLS protections to be undermined when administrators use --skip-verify with self-signed certificates but do not pass -cacert; the CLI may fall back to fetching stored CA certificates, enabling a network-level attacker to perform a man-in-the-middle, view basic auth headers, and harvest credentials. SUSE Rancher issued patches (v2.13.2, v2.12.6, v2.11.10, v2.10.11) and advises users unable to upgrade to always pass explicit CA certificates with -cacert.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.