Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sohee Kim

Researcher fromU.C. Berkeley
#28302of 56,330
9.5Total CVSS
Vulnerabilities · 1
PT-2026-53861
9.5
2026-06-30
Suse · Rancher · CVE-2026-44946
**Name of the Vulnerable Software and Affected Versions** Rancher versions 2.14.0 through 2.14.2 Rancher versions 2.13.0 through 2.13.6 Rancher versions 2.12.0 through 2.12.10 Rancher versions 2.11.0 through 2.11.14 **Description** A SAML authentication replay issue exists in the Assertion Consumer Service (ACS) handler. The system fails to enforce the one-time use of SAML assertions, which are XML-based tokens used to communicate authentication and authorization information between an Identity Provider and a Service Provider. This missing replay protection allows an attacker who captures a valid SAML response—via man-in-the-middle attacks, compromised clients, or logs—to replay the response to authenticate without the victim's credentials. Successful exploitation can lead to unauthorized access, full cluster management takeover, and privilege escalation. **Recommendations** Upgrade Rancher versions 2.14.0 through 2.14.2 to 2.14.3. Upgrade Rancher versions 2.13.0 through 2.13.6 to 2.13.7. Upgrade Rancher versions 2.12.0 through 2.12.10 to 2.12.11. Upgrade Rancher versions 2.11.0 through 2.11.14 to 2.11.15.