A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
https://github.com/rancher/rancher/security/advisories/GHSA-q82v-h4rq-5c86