CVE-2026-44945

Rancher: Unintended Proxy or Intermediary ('Confused Deputy') (CVE-2026-44945)

criticalEPSS 0.6%

Affected

  • Rancher/Rancher 2.14.4..*
  • Rancher/Rancher 2.13.8..*
  • Rancher/Rancher 2.12.12..*
  • Rancher/Rancher 2.11.16..*

Description

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

RancherRancher
2.11.162.12.122.13.82.14.4

Metrics

9.1
Source: nvd-v3
44.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-05 10:00 UTC
CWE-441, CWE-497

Weakness classes (CWE)

  • CWE-441Class

    Unintended Proxy or Intermediary ('Confused Deputy')

    The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

    cwe.mitre.org →
  • CWE-497Base

    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-06 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-44945","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-44945","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-08-05 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-44945","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-08-05 10:17 UTC· meissner@suse.de
    • Affected: Rancher
    • Description: A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-441

Linked advisories