SAML Authentication Replay Vulnerability in Rancher by Rancher Labs
CVE-2026-44946
9.5CRITICAL
What is CVE-2026-44946?
A vulnerability in the Assertion Consumer Service (ACS) handler of Rancher can be exploited due to the lack of enforcement for one-time use of SAML assertions. This may permit attackers to perform person-in-the-middle attacks, intercepting and using SAML assertions to gain unauthorized access to the system. This issue impacts Rancher versions prior to 2.14.3, making it crucial for users to upgrade to mitigate potential security risks.
Affected Version(s)
Rancher 2.14.0 < 2.14.3
Rancher 2.13.0 < 2.13.7
Rancher 2.12.0 < 2.12.11
References
CVSS V4
Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Corban Villa corban.villa@berkeley.edu of a U.C. Berkeley security research project by: Austin Chu, Sohee Kim, and Corban Villa