We found results for “”
CVE-2024-58260
Good to know:
Date: October 2, 2025
A vulnerability has been identified within Rancher Manager where a missing server-side validation on the ".username" field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Incorrect Authorization
CWE-863Top Fix
Upgrade Version
Upgrade to version https://github.com/rancher/rancher.git - v2.9.12;https://github.com/rancher/rancher.git - v2.10.10;https://github.com/rancher/rancher.git - v2.11.6;https://github.com/rancher/rancher.git - v2.12.2
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


