Replay Attack Vulnerability in Rancher Manager by Rancher
CVE-2026-75034

7.4HIGH

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-75034?

A flaw in Rancher Manager allows an attacker to exploit insufficient protection against SAML assertion replay. The issue arises from the method used to cache consumed assertion IDs within a per-process scope, meaning that only the replica pod aware of the original request can detect a replay. Consequently, in a high-availability deployment, an attacker can capture an assertion and replay it to other replicas, potentially gaining unauthorized access to multiple sessions. This vulnerability emphasizes the need for enhanced security measures in managing SAML assertions within Rancher Manager.

Affected Version(s)

Rancher 0 < 2.15.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wade Sparks
.