CVE-2026-71404

HIGH CVSS 3.1: 8.7 EPSS 0.25%
Updated Sep 18, 2026
Suse
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions before 2.15.1
Fixed In 2.15.1
Type CWE-639 (Authorization Bypass)
Vendor Suse
Public PoC No

A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permissions of every principal bound to it.

The change persists after the malicious GlobalRole is deleted. This issue affects Rancher: before 2.15.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Suse Rancher
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
2.15.1