{"id":"CVE-2021-4200","aliases":["GHSA-hx8w-ghh8-r4xf"],"url":"https://o3.security/vulnerability/CVE-2021-4200","summary":"Write access to the catalog for any user when restricted-admin role is enabled in Rancher","details":"A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.","published":"2022-05-02T12:16:26.337Z","modified":"2026-08-07T16:57:46.355074Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/rancher/rancher","fixedVersion":"2.6.4"},{"ecosystem":"Go","name":"github.com/rancher/rancher","fixedVersion":"2.5.13"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1193992"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:57:46.355074Z"}}