« Volver al listado

CVE-2026-44945

Estado: Pendiente de análisisCrítica (9.1)—

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages.

This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada de privilegios en servicio remoto (Rancher) que requiere autenticación (PR:H). Usuario autenticado explota middleware de suplantación para obtener acceso administrativo al plano de control y clústeres downstream.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44945",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44945",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-05T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "meissner@suse.de",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "meissner@suse.de",
      "affectedData": [
        {
          "repo": "https://github.com/rancher/rancher",
          "vendor": "SUSE",
          "product": "Rancher",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "2.11.16",
                  "status": "unaffected"
                }
              ],
              "version": "2.11.0",
              "lessThan": "2.11.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "2.12.12",
                  "status": "unaffected"
                }
              ],
              "version": "2.12.0",
              "lessThan": "2.12.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "2.13.8",
                  "status": "unaffected"
                }
              ],
              "version": "2.13.0",
              "lessThan": "2.13.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "2.14.4",
                  "status": "unaffected"
                }
              ],
              "version": "2.14.0",
              "lessThan": "2.14.2",
              "versionType": "semver"
            }
          ],
          "packageName": "Rancher",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-05T10:17:27.460",
  "references": [
    {
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44945",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://github.com/rancher/rancher/pull/55983",
      "source": "meissner@suse.de"
    },
    {
      "url": "https://github.com/rancher/rancher/security/advisories/GHSA-v584-7w32-jwpq",
      "source": "meissner@suse.de"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "meissner@suse.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-441"
        },
        {
          "lang": "en",
          "value": "CWE-497"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user\n global role can gain full administrative access to the Rancher control \nplane and transitively to all downstream clusters it manages.\n\nThis issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2."
    }
  ],
  "lastModified": "2026-09-01T20:54:51.287",
  "sourceIdentifier": "meissner@suse.de"
}