CVE-2025-67601: Suse Rancher
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
Affected products
- Suse Rancher: from 2.10.0, before 2.10.11 (fixed in 2.10.11); from 2.11.0, before 2.11.10 (fixed in 2.11.10); from 2.12.0, before 2.12.6 (fixed in 2.12.6); from 2.13.0, before 2.13.2 (fixed in 2.13.2)
Published 2026-02-25. Last modified 2026-06-17.