CVE-2026-44947 Details
Description
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.
A vulnerability exists in Rancher versions 2.13.0 prior to 2.13.7 and 2.14.0 prior to 2.14.3, within the legacy Project Role Template Binding (PRTB) reconciler. This issue allows users to retain unauthorized Pod Security Admission (PSA) permissions even after an administrator has removed those permissions from a RoleTemplate. The problem arises because the PRTB reconciler fails to clean up associated PSA ClusterRoles and ClusterRoleBindings when the 'updatepsa' permission is revoked, leaving users with persistent, unauthorized capabilities to modify PSA enforcement across project namespaces.
Users can upgrade to Rancher versions 2.14.3 or 2.13.7, where this vulnerability has been patched. For those unable to upgrade immediately, it is recommended to manually delete stale PSA ClusterRoles and ClusterRoleBindings that reference RoleTemplates no longer assigned 'updatepsa' permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rancher/rancher/security/advisories/GHSA-c4rp-wgqc-mfhc | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |