CVE detail
CVE-2021-25320 — CVE-2021-25320
Published 2021-07-15 · Modified 2026-06-17 · Vendor rancher · Product rancher · Source nvd
CRITICAL
severity
CVSS-derived band
0.0086
EPSS probability
exploitation probability, 30d
55.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9; Rancher versions prior to 2.4.16.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References