CVE-2025-67601

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido identificada dentro de Rancher Manager, donde el uso de certificados CA autofirmados y pasar la bandera -skip-verify al comando de inicio de sesión de Rancher CLI sin pasar también la bandera –cacert resulta en que la CLI intenta obtener certificados CA almacenados en la configuración 'cacerts' de Rancher.

03 Mar 2026, 16:26

Type Values Removed Values Added
References () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-67601 - () https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-67601 - Issue Tracking
References () https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p - () https://github.com/rancher/rancher/security/advisories/GHSA-mc24-7m59-4q5p - Vendor Advisory
CPE cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
First Time Suse
Suse rancher

25 Feb 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 11:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67601

Mitre link : CVE-2025-67601

CVE.ORG link : CVE-2025-67601


JSON object : View

Products Affected

suse

  • rancher
CWE
CWE-295

Improper Certificate Validation