CVE-2025-71261
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
16/06/2026
Last modified:
16/06/2026
Description
An attacker with network-level access between the SUSE Virtualization <br />
and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it <br />
to bypass TLS as a security control.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH



