A vulnerability has been identified within Rancher 
Manager, where after removing a custom GlobalRole that gives 
administrative access or the corresponding binding, the user still 
retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Suse
         Suse rancher  | 
|
| Vendors & Products | 
        
        Suse
         Suse rancher  | 
Wed, 29 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Wed, 29 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability has been identified within Rancher Manager, where after removing a custom GlobalRole that gives administrative access or the corresponding binding, the user still retains access to clusters. This only affects custom Global Roles that have a * on * in * rule for resources or have a * on * rule for non-resource URLs | |
| Title | Rancher user retains access to clusters despite Global Role removal | |
| Weaknesses | CWE-281 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: suse
Published: 2025-10-29T14:54:04.162Z
Updated: 2025-10-29T15:26:02.274Z
Reserved: 2023-05-04T08:30:59.323Z
Link: CVE-2023-32199
Updated: 2025-10-29T15:25:32.337Z
Status : Awaiting Analysis
Published: 2025-10-29T15:15:40.260
Modified: 2025-10-30T15:03:13.440
Link: CVE-2023-32199
No data.
ReportizFlow