logo

Rancher Flaw Allows Malicious Plugins to Hijack Kubernetes Clusters

ID: 7b10ef43-7154-5a84-a97e-780431c1e3b4

STIX ID: report--7b10ef43-7154-5a84-a97e-780431c1e3b4

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Ddos

...
...

SUSE Rancher disclosed CVE-2026-25705: a high-severity (CVSS 8.4) path traversal in the Extensions UIPlugin compressed Endpoint that allows malicious UI extensions to write or overwrite files outside their intended directory, enabling actions from binary hijacking and cluster tampering to full management-plane compromise. Patched releases are available (v2.14.1, v2.13.5, v2.12.9, v2.11.13); there is no workaround, and administrators are urged to only install trusted extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.