Rancher Flaw Allows Malicious Plugins to Hijack Kubernetes Clusters
ID: 7b10ef43-7154-5a84-a97e-780431c1e3b4
STIX ID: report--7b10ef43-7154-5a84-a97e-780431c1e3b4
Feed Name: securityonline.info
SUSE Rancher disclosed CVE-2026-25705: a high-severity (CVSS 8.4) path traversal in the Extensions UIPlugin compressed Endpoint that allows malicious UI extensions to write or overwrite files outside their intended directory, enabling actions from binary hijacking and cluster tampering to full management-plane compromise. Patched releases are available (v2.14.1, v2.13.5, v2.12.9, v2.11.13); there is no workaround, and administrators are urged to only install trusted extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
