CVE-2026-44945
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/08/2026
Última modificación:
06/08/2026
Descripción
*** Pendiente de traducción *** A privilege escalation vulnerability exists in Rancher&#39;s impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user<br />
global role can gain full administrative access to the Rancher control <br />
plane and transitively to all downstream clusters it manages.<br />
<br />
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.
Impacto
Puntuación base 3.x
9.10
Gravedad 3.x
CRÍTICA


