CVE-2026-59675 – SUSE Rancher
“A critical Rancher flaw can turn standard user access into administrative control across the entire managed cluster environment.”
SUSE Rancher is affected by two significant vulnerabilities. CVE-2026-44945 has a CVSS score of 9.1, Critical severity, and allows an authenticated user with the default user global role to gain full administrative access to the Rancher control plane and downstream clusters. CVE-2026-59675 has a CVSS score of 7.5, High severity, and allows an unauthenticated attacker to exhaust Rancher Manager memory through oversized login requests when API audit logging is enabled.
Fixed Rancher releases address the privilege escalation and denial-of-service paths, protecting centralized management of downstream Kubernetes clusters.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-770