CVE-2026-44947: Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rancherto a version that resolves this vulnerability.Fixed in 2.13.7 - Upgrade
Upgrade
Rancherto a version that resolves this vulnerability.Fixed in 2.14.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44947?
CVE-2026-44947 has a risk rating of 53.
How do I fix CVE-2026-44947?
To fix CVE-2026-44947, upgrade Rancher to the latest version where the issue is resolved.
What versions are affected by CVE-2026-44947?
CVE-2026-44947 affects Rancher versions 2.13.0 through 2.13.7 and 2.14.0 through 2.14.3.
What is the impact of CVE-2026-44947?
The impact of CVE-2026-44947 is the retention of unauthorized Pod Security Admission permissions after role downgrade.
Who is affected by CVE-2026-44947?
Users of Rancher who downgrade RoleTemplates without proper clean-up are affected by CVE-2026-44947.