VDB
CVE-2026-44947
CVE-2026-44947
PUBLISHED
CVSS 6.9 MEDIUM
Reported by suse · Published June 30, 2026
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.
Risk Scores
CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE | Rancher | 2.13.0, 2.14.0 |
| SUSE | Rancher | 2.13.0, 2.14.0 |
Timeline
- Jun 30, 2026 CVE Published
- Jun 30, 2026 CVE Updated
- Jul 1, 2026 EPSS Score
- Jul 1, 2026 Coalition ESS Score