CVE-2025-23389: Suse Rancher
High severity, CVSS 8.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.
Affected products
- Suse Rancher: from 2.8.0, before 2.8.13 (fixed in 2.8.13); from 2.9.0, before 2.9.7 (fixed in 2.9.7); from 2.10.0, before 2.10.3 (fixed in 2.10.3)
Published 2025-04-11. Last modified 2026-06-17.