Home
CRITICAL: 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
2.8.0 (semver) before 2.8.14
affected
2.9.0 (semver) before 2.9.8
affected
2.10.0 (semver) before 2.10.4
affected
Description
A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.
Problem types
CWE-266: Incorrect Privilege Assignment
Product status
2.8.0 (semver) before 2.8.14
2.9.0 (semver) before 2.9.8
2.10.0 (semver) before 2.10.4
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2025-23391
github.com/...ancher/security/advisories/GHSA-8p83-cpfg-fj3g