Suse · Rancher · CVE-2026-44947
**Name of the Vulnerable Software and Affected Versions**
Rancher versions 2.13.0 through 2.13.7
Rancher versions 2.14.0 through 2.14.3
**Description**
A missing clean-up process in the legacy Project Role Template Binding (PRTB) reconciler allows users to retain unauthorized Pod Security Admission (PSA) permissions. This occurs after an administrator removes those permissions from a RoleTemplate, meaning the changes are not properly propagated to the users.
**Recommendations**
Update Rancher versions 2.13.0 through 2.13.7 to a version newer than 2.13.7.
Update Rancher versions 2.14.0 through 2.14.3 to a version newer than 2.14.3.