CVE-2026-44945 PUBLISHED

Cross-Cluster Impersonation Confused-Deputy Privilege Escalation

Assigner: suse
Reserved: 08.05.2026 Published: 05.08.2026 Updated: 05.08.2026

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.

This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor SUSE
Product Rancher
Versions Default: unaffected
  • affected from 2.11.0 to 2.11.16 (excl.)
  • affected from 2.12.0 to 2.12.12 (excl.)
  • affected from 2.13.0 to 2.13.8 (excl.)
  • affected from 2.14.0 to 2.14.2 (excl.)

Credits

  • This vulnerability was discovered and reported by @BenTheCyberOne. finder

References

Problem Types

  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy') CWE
  • CWE-497 Exposure of sensitive system information to an unauthorized control sphere CWE