Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-44945

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
05/08/2026
Última modificación:
06/08/2026

Descripción

*** Pendiente de traducción *** A privilege escalation vulnerability exists in Rancher&amp;#39;s impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user<br /> global role can gain full administrative access to the Rancher control <br /> plane and transitively to all downstream clusters it manages.<br /> <br /> This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.