CVE-2026-44946
SAML Authentication Replay in Rancher
Description
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
INFO
Published Date :
June 30, 2026, 12:14 p.m.
Last Modified :
June 30, 2026, 12:14 p.m.
Remotely Exploit :
Yes !
Source :
suse
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | CRITICAL | 404e59f5-483d-4b8a-8e7a-e67604dd8afb |
Solution
- Update Rancher to a version that enforces one-time use of SAML assertions.
- Ensure SAML assertion replay protection is enabled.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-44946 vulnerability anywhere in the article.