VDB

CVE-2026-44947

CVE-2026-44947 PUBLISHED CVSS 6.9 MEDIUM

Reported by suse · Published June 30, 2026

A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate.

Risk Scores

CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Affected Products

VendorProductVersions
SUSERancher2.13.0, 2.14.0
SUSERancher2.13.0, 2.14.0

Timeline

  • Jun 30, 2026 CVE Published
  • Jun 30, 2026 CVE Updated
  • Jul 1, 2026 EPSS Score
  • Jul 1, 2026 Coalition ESS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›