CVE-2026-25705Patch

LOWCVSS 8.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI extension could abuse that to: * Overwrite Rancher binaries or configuration to inject code. * Write to /var/lib/rancher/ to tamper with cluster state. * If hostPath volumes are mounted, write to the host node filesystem. * Use this issue to chain with other attack vectors.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-06)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 1Mentions · 2026-05-06: 2PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-06: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 205-0505-06
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-051
Patch1
2026-05-062
Disclosure1Patch1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    SUSE Rancher v2.14.1 fixes an 8.4 CVSS path traversal flaw (CVE-2026-25705) in UI Extensions. Prevent binary hijacking and host access—upgrade immediately! #Rancher #Kubernetes #CyberSecurity #InfoSec #DevOps #CVE202625705 #CloudNative #K8sSecurity https://securityonline.info/suse-rancher-cve-2026-25705-path-traversal-ui-plugin-exploit/ https://t.co/eQQt69cfgm

    Post summary

    SUSE Rancher v2.14.1 addresses CVE‑2026‑25705, a path‑traversal vulnerability in its UI Extensions, and users are urged to upgrade immediately to stop potential binary hijacking and host access.

    00031418
    12.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في رانشر تسمح للبرمجيات الخبيثة باختطاف مجموعات Kubernetes أصدر فريق أمان SUSE Rancher تحذيرًا عاجلًا بشأن ثغرة عالية الخطورة في رانشر، منصة إدارة الحاويات مفتوحة المصدر الرائدة في الصناعة. تم تعقب الثغرة باسم CVE-2026-25705، وتسمح للبرمجيات الخبيثة بالاستفادة من نقاط الضعف في نظام الإضافات. يمكن للمهاجمين استغلال هذه الثغرة لاختطاف مجموعات Kubernetes. يُنصح بتحديث الإصدارات المعنية فورًا. 🔗 للمزيد: https://securityonline.info/suse-rancher-cve-2026-25705-path-traversal-ui-plugin-exploit/

    Post summary

    SUSE Rancher has issued an urgent warning about CVE‑2026‑25705, a high‑severity path‑traversal flaw in its UI plugin that can let attackers hijack Kubernetes groups, and it recommends updating affected versions immediately.

    00030433
    267 followersView on X
  • Enigma-Global@EnigmaGlobalSW
    Disclosure

    Intel Report [HIGH] - A high-severity path traversal vulnerability (CVE-2026-25705) has been identified in SUSE Rancher, a widely-used Kubernetes management platform. The vulnerability exists in the UI plugin mechanism and allows malicious plugins to... https://www.enigma-global.com/og/report/cve-2026-25705-suse-rancher-path-traversal-vulnerability-allows-malicious-ui-mot1i977-9jxu

    Post summary

    Intel reports a high‑severity path traversal CVE‑2026‑25705 in SUSE Rancher, providing basic technical details but no PoC, exploit, or mitigation information.

    0000039
    8 followersView on X

Explore more