All CVEs
Vulnerability intelligence

CVE-2026-44945

SUSE Rancher CWE-441

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.6%
Riskier than 44% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Aug 11, 2026 · latest Aug 11, 2026

Coverage timeline

Related CVEs — SUSE