CVE-2023-32199: Suse Rancher
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
Affected products
- Suse Rancher: before 0.0.0-20251014212116-7faa74a968c2 (fixed in 0.0.0-20251014212116-7faa74a968c2)
Published 2025-10-29. Last modified 2026-06-17.