Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-44945
Description
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/rancher/rancher/pull/55983mitrepatch
- github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpqmitrevendor-advisory
- bugzilla.suse.com/show_bug.cgimitreissue-tracking
News mentions
0No linked articles in our index yet.