Impact
The vulnerability in Rancher Manager’s /v3/users update endpoint allows an attacker who possesses update rights on the user resource to modify a user’s username and principalIds fields. By injecting another identity provider principal, the attacker can bind the victim’s account to that principal. When the owner of the injected principal logs in, the session is mapped to the victim’s account and inherits the victim’s role bindings, effectively hijacking the account.
Affected Systems
The flaw impacts Rancher Manager instances from any version prior to 2.15.1. The affected product is SUSE Rancher.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The description indicates that the attacker must have update rights on users.management.cattle.io. Based on the description, such permissions are normally held by privileged or compromised accounts.
OpenCVE Enrichment