🔐 CVE Alert

CVE-2024-58267

HIGH 8.0

Rancher CLI SAML authentication is vulnerable to phishing attacks

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

CWE CWE-345
Vendor suse
Product rancher
Published Oct 2, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for suse rancher

Be the first to know when new high vulnerabilities affecting suse rancher are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

SUSE / rancher
2.12.0 < 2.12.2 2.11.0 < 2.11.6 2.10.0 < 2.10.10 2.9.0 < 2.9.12

References

NVD ↗ CVE.org ↗ EPSS Data ↗
bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-58267 github.com: https://github.com/rancher/rancher/security/advisories/GHSA-v3vj-5868-2ch2