Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-44945: Rancher Privilege Escalation: Admin Access to All Clusters
CVE-2026-44945
CVE-2026-44945
Summary
A specific type of user in Rancher can gain full control over the system and all clusters it manages. This means they can make changes to the system and its clusters without needing proper authorization. To fix this, update to the latest version of Rancher, at least 2.11.16, 2.12.12, 2.13.8, or 2.14.2.
What to do
- Update suse rancher to version 2.11.16.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| suse | rancher |
< 2.11.16 Fix: upgrade to 2.11.16
|
Original title
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full ...
Original description
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
nvd CVSS3.1
9.1
Vulnerability type
CWE-441
CWE-497
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026