CVE-2026-44946

EUVD-2026-40304
A SAML authentication replay vulnerability in Rancher's Assertion
 Consumer Service (ACS) handler did not enforce 
one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21.53%
Affected Products (NVD)
VendorProductVersion
suserancher
2.11.0 ≤
𝑥
< 2.11.15
suserancher
2.12.0 ≤
𝑥
< 2.12.11
suserancher
2.13.0 ≤
𝑥
< 2.13.7
suserancher
2.14.0 ≤
𝑥
< 2.14.3
𝑥
= Vulnerable software versions