CVE-2026-44946
A SAML authentication replay vulnerability in Rancher's Assertion
Consumer Service (ACS) handler did not enforce
one-time use of SAML assertion, potentially allowing person in the middle attacks against Rancher, affecting Rancher 2.14.0 before 2.14.3,
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/rancher/rancher/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44946.json, https://github.com/rancher/rancher/security/advisories/GHSA-c5jm-xcmq-9j95, https://nvd.nist.gov/vuln/detail/CVE-2026-44946