


Perceptive Security
SOC/SIEM Consultancy

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the def…
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 13:01:10
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
A critical privilege escalation vulnerability has been identified in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated user with only the default global user role can exploit this flaw to gain full administrative access to the Rancher control plane. This administrative access transitively extends to all downstream Kubernetes clusters managed by Rancher. The vulnerability affects multiple Rancher versions across four major release lines: 2.11.x before 2.11.16, 2.12.x before 2.12.12, 2.13.x before 2.13.8, and 2.14.x before 2.14.2. The issue has been documented in SUSE's Bugzilla, and a fix has been submitted via a pull request on the official Rancher GitHub repository. A GitHub Security Advisory (GHSA-v584-7w32-jwpq) has also been published. Organizations running affected versions of Rancher should upgrade immediately to mitigate the risk of unauthorized administrative access.
Technical details
Mitigation steps:
Affected products:
Rancher 2.11.0 - 2.11.15
Rancher 2.12.0 - 2.12.11
Rancher 2.13.0 - 2.13.7
Rancher 2.14.0 - 2.14.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44945
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44945
https://github.com/rancher/rancher/pull/55983
https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
