CVE-2026-44946
SAML Authentication Replay in Rancher
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
| CWE | CWE-294 |
| Vendor | suse |
| Product | rancher |
| Published | Jun 30, 2026 |
| Last Updated | Jun 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for suse rancher
Be the first to know when new unknown vulnerabilities affecting suse rancher are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SUSE / Rancher
2.14.0 < 2.14.3 2.13.0 < 2.13.7 2.12.0 < 2.12.11 2.11.0 < 2.11.15
References
Credits
Corban Villa [email protected] of a U.C. Berkeley security research project by: Austin Chu, Sohee Kim, and Corban Villa