CVE-2023-32199: Suse Rancher

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs

Affected products

  • Suse Rancher: before 0.0.0-20251014212116-7faa74a968c2 (fixed in 0.0.0-20251014212116-7faa74a968c2)

Published 2025-10-29. Last modified 2026-06-17.