securityonline.info 8/11/2026, 2:11:03 AM · external

Critical Rancher Flaw Lets Users Hijack Kubernetes Clusters

Critical Rancher Flaw Lets Users Hijack Kubernetes Clusters
CyberSIXT Evidence Panel
Primary Source github.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical security flaw in SUSE Rancher, tracked as CVE-2026-44945 with a CVSS score of 9.1, allows low-privileged users to escalate privileges and gain full control of the platform through a cross-cluster impersonation vulnerability. The issue affects Rancher versions 2.11.0, 2.12.0, 2.13.0, and 2.14.0, impacting the management of Kubernetes clusters. SUSE has released patches in versions 2.11.16, 2.12.12, 2.13.8, and 2.14.2.

No confirmed exploitation has been reported yet, but organizations are urged to upgrade immediately to mitigate risks. The vulnerability arises from improper authorization checks between clusters.

View Primary Source Via securityonline.info

Article by CyberSIXT