Threat Advisory

Rancher Cross-Cluster Impersonation Flaw Enables Full Privilege Escalation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability identified as CVE-2026-44945 affects SUSE Rancher versions 2.11.0, 2.12.0, 2.13.0, and 2.14.0, allowing a low-privileged user to seize full control of the platform via cross-cluster impersonation with a CVSS score of 9.1. The flaw stems from a confused-deputy problem in Rancher's impersonation middleware, enabling an attacker who controls RBAC on any downstream cluster to authorize themselves to impersonate privileged identities. This vulnerability grants access to all Rancher secrets, including sensitive information such as kubeconfigs, LDAP passwords, OIDC client secrets, and SAML signing keys, as well as modification of GlobalRoleBindings and full admin control. The business impact is severe due to the exposure of critical data and potential for unauthorized modifications.

RECOMMENDATION:

We recommend you to update Rancher to version 2.11.16, 2.12.12, 2.13.8, 2.14.2.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability identified as CVE-2026-44945 affects SUSE Rancher versions 2.11.0, 2.12.0, 2.13.0, and 2.14.0, allowing a low-privileged user to seize full control of the platform via cross-cluster impersonation with a CVSS score of 9.1. The flaw stems from a confused-deputy problem in Rancher's impersonation middleware, enabling an attacker who controls RBAC on any downstream cluster to authorize themselves to impersonate privileged identities. This vulnerability grants access to all Rancher secrets, including sensitive information such as kubeconfigs, LDAP passwords, OIDC client secrets, and SAML signing keys, as well as modification of GlobalRoleBindings and full admin control. The business impact is severe due to the exposure of critical data and potential for unauthorized modifications.

RECOMMENDATION:

We recommend you to update Rancher to version 2.11.16, 2.12.12, 2.13.8, 2.14.2.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu