
Critical Rancher Flaw Lets Authenticated Users Take Over All Managed Kubernetes Clusters
SUSE has fixed a critical privilege-escalation vulnerability in Rancher that could allow a low-privileged authenticated user to seize administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. Tracked as CVE-2026-44945 and GitHub advisory GHSA-v584-7w32-jwpq, the issue carries a CVSS v3.1 score of 9.1 and is classified as CWE-441, or an […]
The post Critical Rancher Flaw Lets Authenticated Users Take Over All Managed Kubernetes Clusters appeared first on Cyber Security News.