A security vulnerability exists in the Rancher Manager API routes that serve a small set of public UI settings without authentication. These routes were intended to be read-only, but a request-parsing behavior in the underlying Norman API framework allowed a remote, unauthenticated user with network access to the Rancher server to modify the values of those public settings.
Because one of these settings is rendered as raw HTML on the Rancher login page, an unauthenticated attacker could persist attacker-controlled content that is then executed in the browser of any user who opens the login page, in the Rancher origin. This can lead to disclosure of the local administrator bootstrap password or hijacking of an active administrator session, and therefore to full administrative control of the Rancher installation and of the downstream clusters it manages.
The attacker requires network access to the Rancher server endpoint. No Rancher account, credentials, or prior privileges are required.
A legitimate user must subsequently open the Rancher login page for the stored content to take effect. No other deliberate action from that user is required.
Deployments in a default configuration are affected; no non-default feature or setting needs to be enabled.
The fix hardens the unauthenticated Rancher API router so that the public settings endpoints are strictly read-only. Request parameters that could reinterpret the effective HTTP method of a request are now stripped before the request reaches the management API handler, so requests to these unauthenticated routes can no longer result in a write to a setting.
The change is server-side only and does not alter the values or behavior of the settings themselves, so no user action beyond upgrading is required.
Patched versions of Rancher include releases v2.15.2, v2.14.6, v2.13.10, v2.12.14, and v2.11.18.
Administrators who suspect their installation was targeted before upgrading should review the current values of the public UI settings (for example ui-pl , first-login , ui-banners , ui-brand , ui-issues , and ui-default-landing ) and restore any unexpected values, rotate the local administrator password, and invalidate existing administrator tokens and sessions.
No workaround fully addresses the issue other than upgrading to a patched version. Users who cannot upgrade immediately can reduce exposure by:
Restricting network access to the Rancher server endpoint to trusted networks and clients.
Placing Rancher behind a reverse proxy, WAF, or ingress policy that rejects requests to the unauthenticated /v3/settings/* endpoints carrying HTTP method-override parameters or request bodies, allowing only plain read requests.
Monitoring the values of the public UI settings listed above for unexpected changes.
This vulnerability was discovered and reported by @StopWar .
If you have any questions or this advisory:
Reach out to the SUSE Rancher Security team for security related inquiries.
Open an issue in the Rancher repository.
Verify our support matrix and product support life cycle .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
