A critical security flaw in SUSE Rancher, tracked as CVE-2026-44945 with a CVSS score of 9.1, allows low-privileged users to escalate privileges and gain full control of the platform through a cross-cluster impersonation vulnerability. The issue affects Rancher versions 2.11.0, 2.12.0, 2.13.0, and 2.14.0, impacting the management of Kubernetes clusters. SUSE has released patches in versions 2.11.16, 2.12.12, 2.13.8, and 2.14.2.
No confirmed exploitation has been reported yet, but organizations are urged to upgrade immediately to mitigate risks. The vulnerability arises from improper authorization checks between clusters.