Impact
A privileged escalation flaw exists in Rancher’s impersonation middleware, where an authenticated user with the default global role can impersonate as any account and gain complete administrative control of the Rancher control plane. This allows the attacker to modify, delete, or exfiltrate critical resources and to control all downstream clusters managed by Rancher, thereby compromising confidentiality, integrity, and availability. The weakness stems from improperly protected impersonation logic.
Affected Systems
The affected product is SUSE Rancher. Vulnerable versions include all releases from 2.11.0 up to before 2.11.16, from 2.12.0 up to before 2.12.12, from 2.13.0 up to before 2.13.8, and from 2.14.0 up to before 2.14.2.
Risk and Exploitability
The CVSS score for this vulnerability is 9.1, indicating critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated account with the default Global role; the attacker can then use the impersonation endpoint to elevate privileges and access all clusters. The vulnerability can be exploited by any user who has been granted the default role, so the risk is high in environments where that role is misassigned or overly granted.
OpenCVE Enrichment