8.4
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Description
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to: * Overwrite Rancher binaries or configuration to inject code.
* Write to /var/lib/rancher/ to tamper with cluster state.
* If hostPath volumes are mounted, write to the host node filesystem.
* Use this issue to chain with other attack vectors.
* Write to /var/lib/rancher/ to tamper with cluster state.
* If hostPath volumes are mounted, write to the host node filesystem.
* Use this issue to chain with other attack vectors.
Basic Information
ID
CVE-2026-25705
Source
suse
Published
May 13, 2026 at 08:00
Modified
May 13, 2026 at 08:01
Affected Product
Vendor
SUSE
Product
rancher
Version
2.14.0
Affected Versions
SUSE rancher 2.14.0
SUSE rancher 2.13.0
SUSE rancher 2.12.0
SUSE rancher 2.10.11
SUSE rancher 2.13.0
SUSE rancher 2.12.0
SUSE rancher 2.10.11