CVE-2025-67601
Received
Received - Intake
Certificate Validation Bypass in Rancher CLI Using -skip-verify Flag
Publication date: 2026-02-25
Last updated on: 2026-03-03
Assigner: SUSE
Description
Description
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| suse | rancher | From 2.10.0 (inc) to 2.10.11 (exc) |
| suse | rancher | From 2.11.0 (inc) to 2.11.10 (exc) |
| suse | rancher | From 2.12.0 (inc) to 2.12.6 (exc) |
| suse | rancher | From 2.13.0 (inc) to 2.13.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |