CVE-2026-44946: SAML Authentication Replay in Rancher
Published Jun 30, 2026
·Updated
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
Affected Software
5 affected components
Rancher Labs Rancher>2.14.0<=2.14.3
SUSE rancher>=2.11.0<2.11.15
SUSE rancher>=2.12.0<2.12.11
SUSE rancher>=2.13.0<2.13.7
SUSE rancher>=2.14.0<2.14.3
Event History
Jun 30, 2026
CVE Published
via MITRE·12:14 PM
Data Sourced
via MITRE·12:14 PM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44946?
CVE-2026-44946 has a risk rating of 55.
2
How do I fix CVE-2026-44946?
To mitigate CVE-2026-44946, upgrade Rancher to version 2.14.3 or later.
3
What systems are affected by CVE-2026-44946?
CVE-2026-44946 affects Rancher versions prior to 2.14.3.
4
What type of vulnerability is CVE-2026-44946?
CVE-2026-44946 is a SAML authentication replay vulnerability.
5
What impact does CVE-2026-44946 have on Rancher?
CVE-2026-44946 can allow person in the middle attacks against we services using Rancher's Assertion Consumer Service.