CVE-2025-67601Disclosure(suse / rancher)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rancher

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
rancher

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-03-021
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-67601 (CVSS:8.3, HIGH) is Undergoing Analysis. A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski..https://nvd.nist.gov/vuln/detail/CVE-2025-67601 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new high‑severity vulnerability (CVE‑2025‑67601) has been identified in Rancher Manager involving self‑signed CA certificates, but no PoC, exploit, or patch details are provided.

    0000051
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-67601 A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command… https://www.cve.org/CVERecord?id=CVE-2025-67601

    Post summary

    A vulnerability in Rancher Manager allows bypassing certificate verification when using self‑signed CA certificates with the -skip-verify flag in the Rancher CLI login command.

    0000071
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-67601 Rancher Manager CLI Authentication Bypass via Self-Signed Certificate Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-67601

    Post summary

    A new authentication bypass vulnerability (CVE-2025-67601) in Rancher Manager CLI involving self-signed certificate handling has been disclosed.

    0000025
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-67601** pertains to a security flaw within Rancher Manager, an open-source platform for managing Kubernetes clusters. The vulnerability arises when users employ self-signed CA certificates and invoke the Rancher CLI login command with the `-skip-verify` flag **without** specifying the `--cacert` flag. Under these conditions, the CLI attempts to retrieve CA certificates stored in Rancher’s `cacerts` setting, potentially leading to unintended behaviors or security issues. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-67601

    Post summary

    CVE-2025-67601 is a vulnerability in Rancher Manager’s CLI that can cause unintended behavior when using self‑signed certificates with the -skip-verify flag and no --cacert, but no PoC, exploit, or patch is mentioned.

    0000043
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuserancher---

Explore more