Rancher PrivEsc via Impersonate Middleware (Pre-2.14.2)
CVE-2026-44945 Published on August 5, 2026
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
Vulnerability Analysis
CVE-2026-44945 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Types
What is a Confused Deputy Vulnerability?
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
CVE-2026-44945 has been classified to as a Confused Deputy vulnerability or weakness.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
Products Associated with CVE-2026-44945
Want to know whenever a new CVE is published for Suse Rancher? stack.watch will email you.
Affected Versions
SUSE Rancher:- Version 2.11.0 and below 2.11.16 is affected.
- Version 2.12.0 and below 2.12.12 is affected.
- Version 2.13.0 and below 2.13.8 is affected.
- Version 2.14.0 and below 2.14.2 is affected.