LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-44945

Published
CVSS9.1
Severitycritical
WeaknessCWE-441
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44945

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44945.