Impact
The GlobalRole controller in Rancher Manager builds the target ClusterRole name from the user-settable annotation authz.management.cattle.io/cr-name, then overwrites that ClusterRole’s rules without verifying that the GlobalRole owns the target. A user granted permission to create or update GlobalRoles can point the annotation to any existing ClusterRole, such as cluster-admin, and revoke the permissions of all principals bound to it. The change persists even after the malicious GlobalRole is removed, effectively causing a permanent loss of privileged access for those affected by the altered ClusterRole.
Affected Systems
SUSE Rancher Manager versions prior to 2.15.1 are affected. Users running any Rancher release earlier than 2.15.1 should verify the version and plan an upgrade.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability represents a high severity authorization bypass. No EPSS data is available, but assuming typical internal user privileges, an attacker who can create or update GlobalRoles—an authenticated action—can target existing ClusterRoles. The attack does not rely on external network reach but requires the attacker to possess delegated GlobalRole management rights. Once the clusterrole is overwritten, the compromise is durable, substantially reducing or revoking cluster-wide permissions for all bound principals. As the vulnerability is not listed in the CISA KEV catalogue, no current known public exploit may exist, but the severity and persistence warrant prompt remediation.
OpenCVE Enrichment