Vulnerability intelligence
CVE-2026-44945
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.6%
Riskier than 44% of all CVEs · checked 2026-09-24
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Aug 11, 2026 · latest Aug 11, 2026
Coverage timeline
-
Critical Rancher Flaw Lets Users Hijack Kubernetes Clusterssecurityonline.info · Aug 11, 2026