CVE-2026-44946

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:rancher:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-30 13:18

Updated : 2026-07-02 19:58


NVD link : CVE-2026-44946

Mitre link : CVE-2026-44946

CVE.ORG link : CVE-2026-44946


JSON object : View

Products Affected

suse

  • rancher
CWE
CWE-294

Authentication Bypass by Capture-replay