GO · JULY 2026 · EARLY WARNING

Rancher Manager Cluster Import Endpoint Vulnerable to Command Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-MHC6-2GFQ-XX62Severity: CRITICAL

An early warning reports a critical command injection vulnerability in Rancher Manager's cluster import endpoint, potentially allowing attackers to execute arbitrary commands on control-plane nodes and gain full control over downstream Kubernetes clusters.

What happened

An early warning indicates a critical command injection vulnerability in the Rancher Manager cluster import endpoint. This vulnerability reportedly allows attackers to inject arbitrary YAML keys and execute malicious commands on control-plane nodes. Successful exploitation could lead to full control over downstream Kubernetes clusters. Affected versions include 2.14.0 to 2.14.1, 2.13.0 to 2.13.5, 2.12.0 to 2.12.9, 2.11.0 to 2.11.13, and 2.10.0 to 2.10.11. The issue appears to be fixed in versions 2.14.2, 2.13.6, 2.12.10, 2.11.14, and 2.10.12 respectively. It is under investigation whether versions prior to 2.10.0 are affected.

Professional software engineers using Rancher Manager are advised to review their clusters' logs and deployment logs for signs of malicious deployments. As a precaution, rotate all service accounts and credentials that may have been compromised. Consult the primary sources for the most accurate and up-to-date information on this vulnerability.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If rancher is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats