What is CVE-2026-44945?
A privilege escalation vulnerability exists in Rancher's impersonation middleware. An authenticated user with the default user global role can gain full administrative access to the Rancher control plane and all downstream clusters.
Azərbaycanca: Rancher-in `impersonation middleware`-də imtiyaz artırma zəifliyi aşkarlanıb. Standart `user` qlobal rolu olan autentifikasiyalı istifadəçi Rancher idarəetmə panelinə və ona bağlı bütün `downstream` klasterlərə tam inzibati giriş əldə edə bilər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is the minimum level of access an attacker needs to exploit CVE-2026-44945?
The attacker must be an authenticated user in Rancher with the default `user` global role.
What is the impact of successfully exploiting CVE-2026-44945?
Successful exploitation results in gaining full administrative access to the Rancher control plane and all downstream clusters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.