CVE-2026-25705
A vulnerability has been identified in Rancher's Extensions where malicious code can be injected in Rancher through a pa
A vulnerability has been identified in Rancher's Extensions where malicious code can be injected in Rancher through a path traversal in the compressedEndpoint field inside a UIPlugin deployment. A malicious UI extension could abuse that to: Overwrite Rancher binaries or configuration to inject code. Write to /var/lib/rancher/ to tamper with cluster state. If hostPath volumes are mounted, write to the host node filesystem. Use this issue to chain with other attack vectors.
HIGH · CVSS 8.4
EPSS 0.00014
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0