CVE-2025-23391: Suse Rancher
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.
Affected products
- Suse Rancher: from 2.8.0, before 2.8.14 (fixed in 2.8.14); from 2.9.0, before 2.9.8 (fixed in 2.9.8); from 2.10.0, before 2.10.4 (fixed in 2.10.4)
Published 2025-04-11. Last modified 2026-06-17.