
A severe vulnerability was disclosed for SUSE Rancher (CVE-2026-44946) https://vuldb.com/vuln/374823
Post summary
A severe vulnerability for SUSE Rancher (CVE-2026-44946) has been disclosed with a reference to the vulnerability database entry.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

A severe vulnerability was disclosed for SUSE Rancher (CVE-2026-44946) https://vuldb.com/vuln/374823
Post summary
A severe vulnerability for SUSE Rancher (CVE-2026-44946) has been disclosed with a reference to the vulnerability database entry.

🚨 CRITICAL - SAML assertion replay in Rancher ACS handler (CVE-2026-44946) Rancher’s SAML Assertion Consumer Service (ACS) handler fails to enforce one-time use of SAML assertions, enabling replay of previously valid authentication responses. The root cause is improper authentication logic / missing replay protection (failure to validate assertion uniqueness and prevent reuse). An attacker who can capture a SAML response (e.g., via man-in-the-middle, compromised client, logs, or other interception points) can replay it to Rancher to authenticate without needing the victim’s credentials, depending on IdP/session conditions. Successful exploitation results in unauthorized access to Rancher, potentially leading to full cluster management takeover, privilege escalation via admin actions, and broad data/control-plane compromise. 👉 Affected: Rancher 2.14.0–2.14.2, 2.13.0–2.13.6, 2.12.0–2.12.10, 2.11.0–2.11.14 | Upgrade to 2.14.3 / 2.13.7 / 2.12.11 / 2.11.15
Post summary
The post discloses a critical SAML assertion replay vulnerability (CVE-2026-44946) and provides patch guidance by urging users to upgrade to the latest supported Rancher releases.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | suse | rancher | - | - | - |