CVE-2026-44946

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:58

Type Values Removed Values Added
CPE cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
First Time Suse
Suse rancher
References () https://github.com/rancher/rancher/security/advisories/GHSA-c5jm-xcmq-9j95 - () https://github.com/rancher/rancher/security/advisories/GHSA-c5jm-xcmq-9j95 - Vendor Advisory, Mitigation

30 Jun 2026, 13:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 13:18

Updated : 2026-07-02 19:58


NVD link : CVE-2026-44946

Mitre link : CVE-2026-44946

CVE.ORG link : CVE-2026-44946


JSON object : View

Products Affected

suse

  • rancher
CWE
CWE-294

Authentication Bypass by Capture-replay