Replay Attack Vulnerability in Rancher Manager by Rancher
CVE-2026-75034
7.4HIGH
What is CVE-2026-75034?
A flaw in Rancher Manager allows an attacker to exploit insufficient protection against SAML assertion replay. The issue arises from the method used to cache consumed assertion IDs within a per-process scope, meaning that only the replica pod aware of the original request can detect a replay. Consequently, in a high-availability deployment, an attacker can capture an assertion and replay it to other replicas, potentially gaining unauthorized access to multiple sessions. This vulnerability emphasizes the need for enhanced security measures in managing SAML assertions within Rancher Manager.
Affected Version(s)
Rancher 0 < 2.15.1