CVE-2026-44946 Details
Description
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
A SAML authentication replay vulnerability has been identified in Rancher's Assertion Consumer Service (ACS) handler, affecting versions 2.14.0 prior to 2.14.3, 2.13.0 prior to 2.13.7, 2.12.0 prior to 2.12.11, and 2.11.0 prior to 2.11.15. The vulnerability arises because Rancher's SAML login process does not enforce the one-time use of SAML assertions, allowing the same signed SAML response to be reused for multiple authenticated sessions. This issue impacts all SAML-based authentication providers supported by Rancher, including Okta, Ping, ADFS, Keycloak, and Shibboleth, as they all utilize the same ACS handler.
Users can upgrade to Rancher versions 2.14.3, 2.13.7, 2.12.11, or 2.11.15, all of which include the necessary fix. For those unable to upgrade, a partial mitigation involves reducing the SAML assertion validity window at the Identity Provider level, which limits the time frame for replaying a captured assertion. Additionally, restricting network access to the Rancher SAML ACS endpoint and enforcing TLS inspection can reduce the likelihood of intercepting SAML traffic, though it does not completely eliminate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/rancher/security/advisories/GHSA-c5jm-xcmq-9j95 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| suse rancher | >= 2.11.0, < 2.11.15 >= 2.12.0, < 2.12.11 >= 2.13.0, < 2.13.7 >= 2.14.0, < 2.14.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |